sssd-kcm-2.7.2-1.el8 >  A b2U][ܩ2$ @?!#"5Ixp(g?FDy8$d úkw^zLAfR͸+3&r!O"|.Im U{I%yj{G+ʗڱrXY#r}Tfh_9;6n ԕJA-R s ŰmGG HhE&ժeSWyLYw1H//IiOSB"&hK}n1/j Q +ahd/4s>yPRm=~Ͻ:6Xi8""qS<c6pyƖh:i1*[W'ztCVBznxJE:^R2<Z+U1VH^{!cF"BF,5D a "@֙9%:%u]-1Yc6`㍮Ij̰օU_fw\83c382de33f08da01968b2a6797b0929ac8042a1d403f0ee05ff678d9e11f46d02fc86ff27a17f4925f5116b7c7051d94c118d2elb2U]xx oJ#j qŹ蠬mGifeF x%_=yH ?N?B4Ig]X G ةDڞ!!YobOoBK`d /$ jPɪ-v|+SwMl2v0q~R&ۗn8` q#=q4FcLjl+m>|EʣL8v`RT:TMj!㮘CJrA$4dyqATCvOrajm\pB(?d   B 'DJRgx         T     0L |99 9(78@9:d>}?}@}G} H} I~ X~Y~(\~L ]~| ^> bdZe_fbldt u vw x y,Csssd-kcm2.7.21.el8An implementation of a Kerberos KCM serverAn implementation of a Kerberos KCM server. Use this package if you want to use the KCM: Kerberos credentials cache.bǼppc64le-01.mbox.centos.orgCentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxppc64le if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-kcm.socket &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.service &>/dev/null || : fi%60OzځA큤A큤bǼ6bǼbǼbǼ5bǼ5bǼ@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh rusvuk2.7.2-1.el82.7.2-1.el82.7.2-1.el8 kcm_default_ccache.build-id9f44690e4bb7d8837af064cbeb80dc6b25ed64sssd-kcm.servicesssd-kcm.socketsssd_kcmsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcmkcm_default_ccache/etc/krb5.conf.d//usr/lib//usr/lib/.build-id/95//usr/lib/systemd/system//usr/libexec/sssd//usr/share/man/man8//usr/share/man/ru/man8//usr/share/man/sv/man8//usr/share/man/uk/man8//usr/share//usr/share/sssd-kcm/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mcpu=power8 -mtune=power8 -funwind-tables -fstack-clash-protectioncpioxz2ppc64le-redhat-linux-gnuASCII textdirectoryELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, interpreter /lib64/ld64.so.2, for GNU/Linux 3.10.0, BuildID[sha1]=959f44690e4bb7d8837af064cbeb80dc6b25ed64, strippedtroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix),R*R&R/RRRRRR(RRR,RRRR RR.R$RRRRR)RRRRR RR RR R!R%R"R#R R+R'R R-RR3utf-8218e54334b3cc7443954e5562bc6ceb5a51fa0ae7d69b7ed56f995f57ab05e52?7zXZ !#,_] b2u Q{LT/~kӽX"=H=O)`5zBmA!+I9'p,ײ׭x̹|+ kg[]Gd:u@8n[bw/ i5F&Hg5͸LϮjQ鷞z$m91fŬsvK qyN"n83_kY/ي. @C`iLY  =#LaKo=COg"a֗qݩQ_>bKǜe5޵=mSDH/LM`z\jݟ$iVe u/m*+(@#7Jrf2wv/ |u #?%N`|4Ќ-QP)/~TjuZ V *[a4P^v-7(k]'X!8S]ϗd h"8Du*-ެG 9 B@aVMo*%'S4" 5vM}hMBfZ"#r[8@t{lح#o&>"| {.H@M,hz )) ibzt|y9Ym}]g{E B<#mb+J*3!}cV3므>c9;ح0:r=8C$ e%18!v4EMjR9`PupK22-Ik?t_d/tuY^nX]҅hc_5e&+jK\~F^2ٖh^$AGfwŲB1՝)}+%lNδi:3YY}bZ EϲԼZլȱkQن5BU*DeMFg HV#& .Oo,zy/! UFLp6_t4}7|O9&O CZCw:Fn\SYCe'@1`|"Ƨe+ /u$M6JM=C! W-A? h{=)f4{m1 _$0ʠɄp$|k$Kc~an8Un% Cυ|n29;$J)^W}GL9^U]6]XD@Ƞ'&є$zJ2)(HZw7ϋkX9N8lth؟_Lγu4B$kkH6{BRQ8IKՇĞfMlpZH0R6&hTv鬲8\o;Ҥ_R=e2GSPh\ Y0˿Ź#lHrů3`}inm'c"wo?_g)>j wyrZ!ݞ5˝<B6B%>u3]6axs 4mX؇wq{6%= tRn7pu>Y^8?1AO:C5=(fs~֭,U'n=XBW@sVX׫;X&F`/Qmة"p*Z u<?:tͦdoR:F`3,F~6]pLSn_SU헊ՖC`':`jiVKŘq:;(J@Yr 8>˧V)`v_vTG.C\q]yS*>˿Ty@8Y溣+9z;t59B'4$I|+i {OPMy+`/]y/Y^!:j<*??IfM)v|t%7_ߗx @lX!${0,f^"=>F`g9kXFyVgBVftcq)Du, ˓dVF 﨎6&4$vQ':ռ"H_}Uiz*#>)V2 ,|=JG鐗<+\SD|5{̼ !fݺA{zS3'AcyfzIjs(՝@Mv`&?RX г FYωBidA1tvژvjoԘMNHZVr3*m7EjCeXt8n#eDڊQ2d&6> n|.qq̄\ߢm׍- b&ᣘCYFt>,ɬl87DM5fBq) o_[ E3?%2$ ݹ q9C.QIZ6u#;# BO ?"@9I S%K) gU\qXo>/o̕CymV&%yy%j]hy _fMyOfv[s a9WdYQGDUS\ZϯŽ"QL}_ĄCUxE40!ˀ u;*n~`5΁kPA' L~OCGA^"Ȉ{5/7@ny <|жz; &|Q-[~Zz4LXSd_Z&A-:ZYޏߤam$s;zݔBuz?#wS=@y!L$DŽ)_x4UK;gY^{g}ۨMn& f1[qr-$;.d.NM(#y%ci@K|hF !8;uAj]Ԓ2dk(d@z AS<;yDUO3^ w rN$Fv'>h+ސ]w."w9\ovRɳ7~.&?!Q,R&;tڥS5y:*W~5rJ{jTijw6RӰӶ nBj.Du}Q/9)e@y֋#V{CFj %AF qVEވSA) ot~Bɟ%JdJ"tZuY߶Ǹ$XԢ W"G'"0t=Mo@Aw +b^֭M>K|24WB^'/Q3ZZypUD!.>nAA s9WERd֋ H~@T``˵eq8hG;A&pq_"]:o?v^yPnM(ERoiҠ=رH/>|}S [\n?NPKtm_kVdž&i9eVd%'t!D:$Oe%,X^A:[àD]r㌜ȁct`I>aĩ&י8pxi,_+ȿO^Aw Ln/>`2g谯[t(J&:'^<w.eE@TD1σ Ĥ\:' x̑)`ͤtiސ f4B-n{#zci|>Sxr,@٫G~sŊj>+4ϖER]J8B]=|{pzAj!>⻎$L2dU6;DS|PalOEhnCW0Zv襝̐xƵT e(J^P*l)d=¯"" jRaA“TgQV64 >b_SMcPݷ3foa} ʖ4+접Qv=TŅWOh&ӯx̪!X=^OG4qǚ/Izq9eR4-ߒS~%uRo!DUI pg jwlQ-[:lqp0Dw!D'YHV -FWy#.A r$1f D8ϖ)rR),pee5<^qTVz!JεHK&{to\/UZ dQ8<3Meq 1eU_BMyq}&nшܡ l5r@MQ0;GjBϵ&{M b0ok;iT`~lv2/27U[?.Yd 9_xU\3 іUcآ E҆[]wr@iGTfZ֑5H5$??+;=cMW85^PXb'Osbm@ D\@L`;Z Mk1ѣ:_ܺ1z.bS1r?EyX&rf/)4 X~d",Lln ^JlޠX6`K,C%Hpz:"ūT QpqȇevStZR5 ;^::w콕P(.0޲kjA;͸ӖD [\9f?Nc/LPdDyFG"ϵ_9QgcvXY;WEc N!69" LvNVHXCW]8oP5ak$U(ʛ4قK`#v!(/UOC;ԮBv%Q$9Y?1^&*ItoG*>ۇ炟Kuec,B0Wz(ۧm@(+Ȭ08*̵ WZE\  8UԔ_/-wПt.MnJ /I2B0?6αwKkLfՙ7]VCKi:EWYȤ~lH]^+ƢϣaVAm쪤;T3) G1Y5O_[D&8TB#9}slHB^vVfUGd`6Ƕ`sFXCD >6I" @(XEɩ&uokE+A)tnN]Oy]8}Z#(LC0KxVGChp;5v@o:{:ζ5.qiQ[ j ;yy bR vrq Nͨ<=P1H#FQ)c%^dS9\̛Xgo\513]X\f/E8.+oj*t3^$ă)b=M27OZDr\9p]2S0|xzSM{G)`:0(R!85Ҍu?UI_+PSk40^.Ͳ,װyd,_0Q1 =Wz$*9Le7 sb†3ccr#ކREgԄ戳 "s߹JNq mzi7w_X"MX~FF5|s4ʒ;P6ZDmci4^*]ϑw4~J͈; 2%J"zWOk@-S͊U˻p4sOJduh𾁛iD=JdB5haM e^XEG Π$/cgae5o ͯM%$.OctzSnS]Em&Ay4rbŒ D1 FAUrB4~b\m0 ]8J x9Ti$cҥ0ABh t4+H5T`Q_dM8˓UfxK3y;|%|2 -dL'#gsN X"[_}L|}كL^k%OB0G$g@8tٜ1}0M#h1[cN/0G>x$pX :cH*^%hЙAb^HF ~Nw*sttqB[bM2ԠߐKKA"lqkshDx2؛ISXЋT!Q{7 TϠ+yZS@ n/bL˰B[TinhAbn:ic Xc(Fkc^ئ)Y( ?l[ͣUdtw$ć'ꉪXs#4/9c %&52z8E #m "i 8,w:4qލE1F os?6 CGMKQC=\W,krL;3>-t*£ٮLI]t?KAi䌞Dwa)^m*( 2{FUoC2d5OAOO.] X1 @PyGBc#a]f&3嶈ޥi8:u9;XDP 11"mڔILĨ֕^ECuTR}O}XzKW\aAyP9bS4L?L-Ync9l[iQ-̱6r ÷a9ȦftZCPVh̉M=X(ӕVZUX'nّx+f_  xg%y&o Mg[NSwv &ړlH #4gal-rO31cZ#45!Eρv v&vѰI`#eJq@.8 ^Kf` I>J*\dB늗 G@m-3C~v og3QbbbĚe JmM}MmSRR%y~kӟ jDM$aY Yߠbam~BBTڳ( s@泠 %J\ `ԉܸurc(he5Dr#F H#vWI"}q|$vPYhX͕ܠFH١)RijMf1>Z+0Rzn;$R,qI>p!t_z#KMD xpL1,џ!e@-(E/}b44.1BlXCFlct TzH{sVm2kAŒN׫Ojoӕ %`-<0Q fW$ ^7ˌw%ꑠcwM6q?pGB`%Xl\t9ZR ,^$0bRh1IŢ^^'B=&d! 㯽81իuSDYQ='>@Xk`6,<&oÙig? %έ5rB&NiöXU KCO(1TeqF$2bb9@՛".zizmԘY:B$B>Rq~`_pS.I99TVN~Ȣn]- JE T?) ^$2T b{/$4WqG yE0p !|MZg_#%)?TH=5.~$\ IA$4Kvƻ3~OU2ʳŒ E5֑|F /[4.=IrpB[ ["w+ (1,"8| 1u/z7^"Brb[WlP]WLU*40Q ïLyeڼW `rLAHMV8 LA5LG 6gԔĎCztxQwL5J6. cjNg@'T *!D?K\S&bW.=Dbm@ műt*@ CzA:|la ҉y,EX)f ކH}/[j[Yÿ 2rH\&8+m"/#aHsRсI,r\x2PX0}iN??>Fy8A4g9E_֦8T1nNj {׶U+>;dƱ@,*-Z*9_^请.QOGvS /8]D._a,HIu%8~4z9+u(!.4$RbH6zG.>PhIf_HA֭V ,Jaݽ A>=Z范X>}Eɟ߰Nٰqa n bg1ܼˈvfkiЫ ?G&شsnѓִ;_Z|oɀ/$wrw a3Iky,>ZRGNǩdeI/`е5PjtqT[kPʌG5^"w7[^z>lwybJip=7\C_!؍699'; mm\JŞ9-7NuM̈ݰ`C$G1il`,@ˑH3Upc3}ttD^H <%S\hӲ7xeۋ(u3IH1Db=$ws0Sڂrγ2tp3`7;`9~-{"okv?{ۭ=خS>gb~g9_UhWJY"KmşI.ơ#-~?{~܉p u@IAwN\Rs2[Sôy$ԝS/U쳏j' C7_6 <<^Ұx7xiєցl ;|-Dh.3C^_a VsS#͛wZM"hOOsܿ!i99ePl_FZ@dw;#DBuDXk +v^o }%>l0? FibPP cRɽl'Ði~ƱLi [D/=j!JI_L @8pN)u_3]X۲łyqvX@Ld As۫V9QވCa7+S3AOО(C|pv99~wv 0Pg*ZI j{ +>:)tT1{R;GNqDSݾ Ēd" DQ.%u7[3KK:$bZ/_(ȥ .!yGVn] =X4퓪b"u{L\iQ~Y=@T!B,RlEAm>^A Mq{&90!?=t[p{"nwdrsX= & ٯ&,c1 8( D6/ x<#C3x&ai8MXdK8!̃9/Σ:I>$/(r`43jUWiv i(AxڒUO3UZkC$gњIrPi^F^96x;&u+xaN*ӛ|I#;7)뤑 Y_z`% أc״FJ]B UFL2lgSs1/e3A؏"cfY.<K:18Ò~joNEג;$q(à2) USC4k^{@Bl߹ LE{]  *5#UBn@_&Tb﹍+P-.pr:JY>6#h7 (sɅh 6+ncQ%/D--LB}?M0FA-^[r'l԰)>g5obw_=؞2b<e݃_ .pXIPcotFn,RN BtPƟ)W4c 6tgc%T7=kM'*V jk8B/%H83)TI19?*~_"^3AX$/mϲx.VۍQ$}z'iDxtBjdXeR=*$0)bQakQ;oݠPuP*_@9x]:<92r(*-B+a k@څTL9v8\¸y% ev\#h1.ԙ v znɡJ"z|ȱ)+&CkG6!*32aRmWZ2aqt^ҵ`E>hO;ra紕r->!U@*c^?q2N%ݼ\ΦcUdIݕN)e6q_ƾm:7]Kl71 agЗi]"ԚM \mi$Ų֍ N;SJl`EhE{(ŀ@z@9jy$:$+Yf& HEkcJo%*Uu1 [0+.ljH<ޔx7ϯ2 ;6z.meP;_D D' y>S*QIRYH;Z'Or3?(ÍDpc8kvL^y"֟xwR} MO!/V1bkl/GjӀ* -S2:$ı{T2$l_Yk` q,6(9NrA52sW^.:V\o|p_lC-K"ܘZ2y(1̈ioOF2"A晙C?dX&UR&k-u}Y{]WFŸmҕ<ͮX!wEƥNM7nRPMb\lDq]sβbU{HjO!wDcx:IcEpL.P)nQd v>|z?Yd꧛z1S|%~ ?!1a 3jy"!zT3n(gm fSNp(xaD<;z@AgmY]PpaU5ԮM_}=WU%u,sZf(:]Oˋ C6:Kp *Ly◔&lR G1ɫnC`9n/'W.:}F;D!c͡jAjs+3I_x8CΑ8d5: 1iG}x'l` H7m|΂|N݄Kw3^ѺIYha;#. {%n!`D}fP|B+:g*k`yAӯ)nΨ9MG- iSyVq  Æ~߯QZȍBMfXàkykg6Th:s.Z6cV`hPA'"?[VhbX4*)-޺&1_:Q%b8R!Nl4>?a:m 'eX(~1mcuWul.lq<:"O#cufHJAC'(ˊT,&|y+aY{ ),Z1 L!SC>[t$]@M&cu Xy(!ׁ/M!\Io;j\ k%w(վgEPD s Xڂid8s1%D/ÔRQvș,HIǣI %JnIX.Ɵ5rkS -p6)ŝrW_[I&P.L̀a,d/blͼU4寳\  op|HUc5O0ݺɆ$ef_$^?z_dN~Gȹ|7lg.*?`Jkg:{;Xv> yޔ&RpCt$(UuTxw5Q3k5n)mI{F X {ԐɆU|* `deه ]$_KxdVI}| ?fp6\oX<Zc]LN/E&h Hk.#5 ŝ-ր a0*<ȥmɓޕ檳$"Nekp*F4k1gW]x v^ ꉻϮ||W?|w .g߂yuq&$NǴO\XQo݂$6yh Zٝz?pi+~h7|ɶ~olu"Au& h ' 4yne?]@Rh't‰wlRj$ s#C΅ $*Ћa/JhLҎCN BSe3xIgMe\oőƘ8`]TpZ&uy +ia 2D]|81T t(d#RTj6hs "Vf '!-8*P[OB.nzr 6-ejk4O}`#ϰ%.8:t>{BUk5\84y9٪RZ5mEU Qa54.$㐒E?!;ed zJhfY>@6^? ٶ87EjcB,r{ɽ,6 ~nDaOE PhI!<J5NEW!-(|zb!;څEn>7 .l@J3{wQz]6m*+WDC}oF Čm5V#6gKe5k]20O SDJτVӪetwl-~͛ N :]ĩb>fKlf6+Sf25Kc[WSÇhbC&`4\!ã ubĽ\{+!hT?>c.BH$+kKmtU/~uhq$w09yP4sUG)Ur$r,w07/{^FwRWu[j1>4~}J`q80`a\M+,S,?[9S|{u:5 * 0~S?0Je/m&%x $0.===L$ؐ.["zA@?&DU.EҔ |i/vd9`š zW@VpP R 4\6ŨȶۻT͑ߺ{oŅ8E(Ř Kɳ aRC++s`^ U ܥeaUÔ+|ڼc?: E.qthu_Eky05~ѯv}'^yd#\Anddb>>/T( B SKq[{Un'!~s]:N gZ'™Z @(R2bVw|"pqk%Wp2<8(hE?茒nrr$ظrRMI JM9&LwA `ߝAդ0tO=LۈW \ J5}H$VXr3S>[eVȷbHP n6m#Elz (Ҥ{zkSI`eB\rv{DK1]@mFn] ; Ƣ+`d'A aኜRLU^ /5C6Mb<&Ν]*nG} ag)^RLRiq+$ZлWP%θA⯁aZN0,U>P eUI-г#>FAZhRuF&<6f5i$sY.~`dD9gTSZ"pV=Hl$ (4x pZFv027G$Km$ }ggdMa/3nadr%ޤr~>LoѳcFPk^{Xs'iB%0}AAPi<_j2IہY+lwGI,eZ,p6x_\Zkrdi[֗Ũ#RP|uiYwkvǼ]V"Xk14 M,E#B=KڨӒƽS;:XD,F۷?q뾩#YA_ygRnzy,g'a}Z덲H:?|Fp,`O޽`~!6q[;fjqZ sxo ` 5Q;:an1=;M.(ekVpE̠ 0">O>db\>lXJ* ֨^J-d@nk2㘿rIBnnKEd=lnPͱWߵqpc(Fșqi:ᩖLnց~OwH}#Z"LrFsvZ6aXE֊e~[r@{+,+)iWfxuVtF9nTRfg*4UQĿguxcb;ti8Ymm3xTj/t~` ofxQim3-l:FMcd m<9jӕq*% 6Ik!;c;.|O=Ď.(V 8XZE W0.ezW2,͖xs+" 8+Jg+u+ Z,8Е<)f/}oR:TlL\cVm$^}o22ֵf-B sՋC3+(TETx2 k *D&&埚SÍC]@b ikO(3> E`ojnGlNs`g&(2d!WU;EME._)]Qtv!e!E̞Tx>A~g*SVlܑawj}Kcf]WfltO8Yڸ5!ATU؋ӂt63|QuNVW_&j rEKz9 3Ho$\k~}O0}v VM5=w!2q?i=E3Y]( m|Z#-6sMн;b g<0"hX)C϶*)",Z)ߗZk9Ŕ?jJSRh[lV'...2m˖?qwoV/jDip%DRP#HW:?ׄI6BDC *ig.O0SFACnKa_7%aj{20G;Ÿf "p}LFd g4W  5C3`8t<~Pvy3[-@JtM[E3 [k@OQFA[,EOe&;HP. .Ah{p>$Pi7j>Yh kɩ@!NN(zu|FJ=Uc\ 0f1 A' btl\|ˠKv@p[|.HP8!q4{]C햋Z%s@ZI9wPl^h@rW[LGB8TFfǖoզɅ͏O![֋+s}R~ϯWgL^}aEW{vuK;Owhu:ÿ́[i dm8vDorYPAQ>M!k^C-Z$dؾ W! ÆL{h u+T`oʵ^\"VEay`1#;Zj^Bd, m }|V_@g- 6"&JkKN@vb[4SԱeoҚӌLR/UX>eS(nWfL%n@:`vᩂOk?hoLB ]=%J࿫ IbS<@) ~聹Q\v gLi2  Y/[$nlIfAR-y$$jJd;pKf$j* h߉sŇ p]]:a9^ƌW`@8W!!1ĈnDX'8F@= fS>0ZpqK# ޲3bf=A;\!;ZG{e n횞`Hg`ncmGc'a~ق0)dbS7sY[G#g3"O9D?QJ/uI}^|`@qD8F|ܵ^_*~i7("Y@&hN0GG Fb5C|VȍLSoJuoie4yT611 #`/\;pfT~?T/]ekyыI@y$x&/~5iw&9t!? %!~hzR38<$9˼`Q.z;GpPE X߱9_ȧ&A<,]E[Y3umLARW &h &z,eΧpWh Au n3k|kvݮ4)JQI/ie|9ij Qhl:f@q:FxH׍Q283yP GJS[<.2u|WO99h2qBC6L*3S5N>:gJ kGQ֣~&ѧ}<'8ҥtϨzekÊ67XTE jNefrP]w '=cQbQˬk#I(# ~,ř 6 꽄'tJu ?=G ""nU80 Hì/C/Su,H%Ezd7E`I\t}? E:Z:A{/B3y"Z>M3ErȰqS!2'_ )klU<q N񔒥aשyӮ7:Z(RW{Ú՞@??JQ!;ĪexJ'ʺjӡ[Nn/&cmnNò$U[{ f\w=JtG(GrG+נ>St_&uL(q:,Q. fԛOVg}FPb v ,a齇<ְ2)ϱGSU3" KQBDw.XD%'.@}b0)oy۰BгH lEnDZP=iqfw*Q˕}[$.xpܮDW,H.fç#|+!FYb 1GP0/g+_+l(7^E='Z%zu51nlM؝K*][jMhExʝQˢ#alVOb #J%O*ܖg*~eQT BF ̡AD}af3ѡ{LȽC&X{f>cO1|P1SnuuϔפJabiԥ`'mō5oH2v"Y@ApQ "gi}m%Zy'I?=h||C: 0] >:P豦~'R+xĮ,1ơ@U~T P0%tܧǏ3piEeG;Ij2)@b>XuF)֤ ޾F_l'WIRRj W%J PмxLf)v(ZrP=?'uًשW%FxMJH Um+{DΝ[9Fҹ 7(.4+R檄e,lJ`Zi"f.hxb5TYۊuut(͕KЩ;@,gv/w9XD[eg86B/~,mF)<5&za54ˁ׎={Z~yʢ:$ۆVl$DGLAU>GB#xd򥟜,n0tӵg;XmL)=9w)}pb!2'^qu_H1rާ2yݗ}Rw ?v2Rq6i>fu[W꣈*nZʆV߄Ay6eH۷_>UڀNp[Rn#>m`?zÄ1zx= ܍G] 7 =J!bLgkz]I–;@puOIB%D3zT#jKi fƎ dxSIϩ?'P?w7p68 t}pBM_m~[G(KVPhsϐ޶*A: 416ئ\IR1 YwN%iXtldfXի%9oHm,G]n!`Qr,X[JhEqb?*1M>F3]2ȥE+Ord{xV$U^>Mk: {/+>9Qp3}VZ Є31 S+GEn#͉lp+%zK!kBzn DL>DZ` o=@=W'=9rkwW()8IyT/T2{v 0<Փ^Co5Rҋ@3K؁`tP}IG4480ްrmD OHd:בR5eC*>F0]H %T%3|yYG/@GO_ROc v|9I'36)Pd~(#tքV;вhyzAm#4aȬ#^E6CvR"뇆Q_a:!!{)&a ZB!t55Kn6jb􌈲Qm\Z)Gss"G4GvMY)Xǣa8}zhguaJ-.0Q!3 Me~uDOD`00!m 9]R V6F|y]z8ȅPV `xkem:v_yl8tyQJD` ˰gIq##+p~~|I'\QGdp0FD2n!_*&8.pR5 ݫ[ 2\po0B8S1*~\铨x >ƳSꉥNȡM̈́,dΒ_cvן9W7X$GyZS|񎛕JK];Oӳ;cͺ;a v/ uRˈC˷ q{ j乙b4Ut*˙27(O6>ތOfREqk=ڮ,s09O3P9,e)C9o Tѯomzd\fL/oqn&CO36dƕ%C0hI~ 3 MNO,UCp,V<\JsH3bFUbeʂm]nwhsPVJz]pm/tڊUk8FL"W` ͺ$mKQ`D`'gCxeP}; G4CFFFkہf @racf;Eτ;tcD ,d(w^q]%w5\*j9%ĚiZ1w# {:1a}AҪYU׊^wУPpI; +:8?9¶o^w ~q n{?f_MI.oYO{EŸ{bXӜEL&IKJpp>#6\W;V@:eV4k|2U(y~ufgsAJeA,4gE-<@` R,Bar3Cc0ZNXr]DJ)rvow ?6uVJczX+d0-(kpgFuyJ#7]OqϤE-+  2:w)m(rTmvvckJkfw3s-7 @e]m'v}D;./Z1㫵YR .,m= c8(@k@cuz57-9myԏ-Y8L-FF6pT_kQ΀e>HSUYuͨ @ puPj%&'Mֹrb KpCc߱Bb`< u0!۰)(g`V|)]\j'z12Ă |tVIR**=Zq憵zQM ϓWٷ+`d0XH,gbݗW o=26o !*/mjhC2Qc1_y[OK}j'r-8NlHw='YL#yc=sϸ3AdDᓏSν8xl=5ѾmC|tȲ^t88 ;4AeSji0 e~dWu;.snOM@źUm;0!&s fvgiB[x$#Ƴ]mADE$Pp"8.)IUFM&|tqksIE[ىK8 դd|f=%iv]REtm1 îKQ&gFZ+;tQ9~XB2~w@6 qu2:T'ܲ49"7{ҕu5&^k^x쨾Srsӂp+Gf`d@Wp=rz><%M ,r`sW0\f zH3Qҷٝi*j =SN[?f$q< ck`L WRo織]FU.bF4r ͝ʽ2?>yu`D;]A}/XPAC5/Mw7kB2I- A8AJFx4{S7(]K{*g)yVtv@A.8wt ,?fM(&U_iUr~iRb}Kᅤ|i8J/P<^8 c ^ :"6@ya\A48]XXpo䑻<.^0Xo\MS|ئ'G pԫ"$<YP:s6?\|[duDwRH,wFչčM<0Ɩi)1?@X.C/-g yv!3!S+  Ua]pTjì"&7(̉cuK[oc`8^妑@dQxc;Er>J.Y6Dg&;%܃f#ۏ_/*@[O vs Ǒ"TZ7"Yn]qVEJs@EvKi' L(_8I!J@ #rgZش8>6냕D :̵mdA]V'8>QqYF0pnr!Qa8 AݨmЮxƒG# Re/UzrIZNo[iC܁?h$Ka% As%½e1a ׆Vn Cl~Q #)7&mAc0~&nxqmj̰mqlJn0rvWN_?F\di oZ6K{l{כbRg_zuķ΁hdkߝIXrخrǰt#,%7Nm>wVǂoVL*!ݰjiRy/8P wQhn ЧJiN*'X}&yNa"uN$*e[:=l k `2]ȴG^ &S0l\Ҙ9}繧1띔/c`|! [iZϗ*oU0+kHlDnZJ8E8sBClW]-CU%F^ ~E^A^bffink46;p)6NKe`Œ[uЯ$͂ wZᚠA _J|kaׁY]_-5`\FE(Mjx]j2=Rr_@DVKH!wq}1FCKZylgX¤?VΏ%3QR =HG{x˒XyNo5y%y j)<>H@mZgxMVelj"VEd)'qK~8QQ_3SV~:(f^PeVԗe 鋔nI&o*ѶwBd+qPmUhF Y!sŲ.2qrsq=%1-L^]47/D`W8cx(T'iSr TGvd./{HJo2FU<Ľ{?Y_(59w;>!r|X-.'S 4#m ohi"J ѩ'~@*3n+M!{%Eb08oF臼Ei'Έ  :Xd־ʆN}4ICkv?C wC}9H@s\cX B2>NcowaJ2ӽoT \ dJ %+s™oGewNVN50n+C8Y7 ФP`m_ szVoֈlea 1y=B(P*nnZU>U/[6d =^iygSOd$AR36\^w"JRh0mr۞I:G2SХQ?Bh,s˔!:/x&ϟd۟t1F p oWf EWi[ _zĹl0?gj GӠ|J(#>>"e786 2Omu՞ٞ_WowtC,1|7`f])6S$;vk2_z$A3= ȈL!lT1RSdȨ$Ź 4!ةV}a 0v4SYXt'}W m "AT8S̗)7‰Q8yIcڰ.7硯H%QIVyfqsm#2TK{_Ll<$t1Dd@6H Hp-t>01bm._Ӑ^CYZ$&u<\ c=)kس6ɩPワt;' DhK-߄nh_d5GlPh˛4f]0J _b4f7'3a`MōN`6NU#V{sE"7e>cevo^o昱TPD`|jz}! ]rh𨻘N ځmBzt!֒b*&9_=IezhQS`N_HəxG ݹk-`vv;eWDif#h EHjJҡICUw%հj&y Xt(dWއ725JXWJQOP'ܒ@oC}RA:"eD5\ bFzϊ8wz-0pv P ŊG~kk!&xwa+ƻoyHرm+LH .Y=ΰV:qNZfk22,U}靴7?v5'Ki6 Z(kf~rJB*)!@#ѽx\B[HƫA? %Lnsy δ@OggϛskYx-t7@"9D.6+Crf"SƐpl67I+̻JL.S >0JTLy}ˈLb\W-Q2Ί^q"=2vnI64`t"8BL:OH)f\҇~JQdǺGڛ*x=t,z}ϑl "c-TΩNp6yɅւ ;Aftl$ DVCr 9o8q@\ݙ7ZuOCi}M=l {ϚzUԛΠC ||=Tڀ 0 Rr/ۤC"|uגM4+rhM*mId4ѩj-5Bן]g{bH[{7A6-$RNZ#eҤLl0>*ƵZۢb?Z t3}>BfO`-h!fp7Є3W8S]F6i #!sbk"?~9֊GF ШYt#;*rlp2ahҁr}c(DnJDb}_!VEvvFNo&BlΖ!<zh=^[e|><{r [7i%0cM PZ jN$_&LE*\㿯ki'%5!여Ӽ~A'fW0vg#5ɻ ;|Ɣ+@9XEYIVCOxd4R[G젳Q_o1 3r>֒)EnXp!NeyL*oC1;B9?*{uly3mZj4?@ (fè:P^PPhZ) qƒxyؠm|#Q߀0Vlj!%;B %RQ̙X+:Ud;۲̳|+h[71pn(L:ûJRcߎ+gCGqO0T~rDĐrߗh⹿U ؓ+BE1_s7m[140EU<`;Ռ4yP'0 G|+Ԗq1YN##{ eq-EvjҎx"Mz 5އquAkB#duƳ#>a,ua-b'>XlO9As¢$lY29 W'>Ohy/ncû:VDS+{Axt +5+Q?U0ΘkUi_=u ;#|4. Hn:ܑg>.z fh[Othvg$ԗFcȅa?&qUԢc?Y "acq1j*~[Z[NѾF#jg9(xF;ɷ+|έ#($]s|1mbE1%O;{_gn&*PL)IaxPn\MCh} }k MŹ5Ç4_&wZsOQ@ aLU`q?֩HFr) >mڒQٗm=Yӥ׊Jd^o\7͇p&+A2͡2 SYe R2vCI$uJtZ +Dj*uB@$kX7R`{|wr7ʻ~h*ԺOT?-t_G-m`4l7w_Y1c\|yH#vږ| *<㥐ΔBNiWnő:G ,B4)!f|}^)pLxW !Uó*c1=P60lz`>x)+rxwF:D:p3SS[ t`jQ?F1!q4̎)._ ;#K";l BW i?v~;&5W%_2zU޳lђ)z"yI ^E m .㳨K5ҧ<й0;)Hs#yn XrHAcw,%딖` ۷P{Fu q :F $bF=2A")bWky3v`@ћ^SyVg҇Ǖ=ME?nR1P1SLm1_Z[[^-P'7xͰ+FF.mUjJBO;.9ٙAÕ UM b=BhYDC$0KXI\ea dLzo&46\C s`.֭-pg.aSEοcWd8$?Pٹ|ۥ7Ww.( P}8jo6v\w)N:=OwS5MO G&*Z阊3iSԔ ND"L걛&n!oIh₢516jC T-Z E'"Ӌl`'ʟJڨ iP)Mbo~dro]* 뾘2wDtk̽ Z*JTkVW1j+pf! ξ^/Q$z`{MH`sIH>3v?Mu.KݔrٖmX5H]ؾ pZ>N X˸f%aiAFLsv¶@ [4_adQ_;PBYn㧙4yԻ_go/cà9#2G7rlm2d,aWly;N!^Pk-|>Sƻe$ŵu|L,Usb.xgh&zE+ܻI@'#[񩕔nY̒hJeBk;OgOQVcbLRnʊj)#]"o/`MH s˃$S_{55 ZAT \򲥷\{Sa&O>S F1g}~C'2C0J+H*zJ&LQK bZs')"X"{ ^N'J;Id$p-KIh`!-;jݾ@@Ո*E3G==*b>c gJŝ^k$S^p\fE@B!0쎢49T&}M08"h!)-;ou.|CVl Y\M>(ǗZdqK7 ߌ/HXv)>lQ0MQ'2i8eS h5Pgo 9fiqb*^2dž` {fyF%m!F9p<ٺćeoUSq?:D٦w0bA+5ٍL<],mC:w?n}H{E[ь+{?a+႙:ya /T zw85~>*и>|kPWN_Γڿ|LJ+-bI3_Đ[Z"6TBbkFS*9dHoOD) {e*vDI(T ҭ -,4%e. %حAé_r>G<#涵j$.$RhAOHGz:.6<mV AѳT~lϗYa0oaOw2MΘf@Q-:錉KfZgqLW|ke|cJ.1 ₧1^3YKUunAX쥳}/3.1Tz((_Yf~ zhY@CXŮݾ*է+t: 1J9 ?2qA'<9#i5 <`}!h4KphiX;!:>;7Ui^n{uf~!pE6+(nȈ'iO҉k@Ou=xf 6% u:`ҝkL[`\s8u:o5$v4~$_[6LJB#!zjF#kt&anifWYB[͎|聀6wLt -t_^n ;z&u),ba#2K-cRLl2HƐG򓭠͎[IISnZ> A>6۷s "~훭e .i&9cjiθ#b$a"Qh ./7䉠 ' R0rT@aKdU/vޔQ(kQoZ3jUm5?FVFr~,5qYOfx`D cB[KM֘׶DsM/uUыM\Cc V[çЦl[WWf\W4<)ժVhLJBmTRK$=8Ag:ec*9Uʞ?f4A0ʚ޶kp9[k9~l˭(RҀ4N^[%&d G{1gټuz%4Oպ_:p̬-:VWkibIuZ!>abFf#*(@j Oi~> @j4Vt"7b_'oc +>̡ES߆pT7_,㜔QdX{rQ޿}-F;.5b,}E ˖^y ugJEl䋩Ğ9{ )$8݀[t4^ J4T<Ҏpݾ).٫U9cP3j1,V2Ƨ#$'K@SX=e7:~~R4WϢRZLK *5p!l_-Ho8sx8DoG'89{%,lB)4jPໄx3>T7rhb'^|2ORD l}vW{ ]s FeFye󬉍cF(Ǖn/05@Qێ'=ⓈԱ\Kz ۟ѷ{Uʏ\A6R&NnWz}a0RJ/O6/a!f U`栘%#@X/_2GBļJ7֧D-ro~L//Q yj} Zl#(}6yeŋx)Xu F(-o-/ FaRD+bg ~ PV?~^DSol~B6Ds7o8@4r\A'E^DwQfMqөg n KK!U>ɶ>+(I@#omMq ht2DBD+dakfMvN(wd-4/.`l9R O{ q -l/#T~H1$}y1d]v2OHW",)/aP cbIsTKqƁ泅DŽ׋`",eЊ4vYϺH\?( [#~ aip60SƼJ\u,#="!EfGPz-s,y_iZWP5*cv{ڔi袮$GB}h$͖vO]Dd'])ۮ-f˺ehuE9uQ,g=yfx7_Zt,Ϫêxa fao9vˮ̈7ńMޑcrfZRㄾWLClݒTcV$}`͢v$%Jלrw5r_clӝNLƏѽ">z M `[$^n X61zҘz#?1p߳&'bGnQ@gfT7clMg[uS2.+A@*Yq2J,*n8| k_Hu%ئy'CXMPp+־hwP9gGO]S0Iț) ^K> ׽AHn q)9KN:ԣkƝbWi:v'/QҮHd\iP2&^%? 3~q}$VcCwP|bbVɘNB] y[& _:C?1ĥpIc1Wըq){JD&N3cWÎdUe-S $GM`0pr<ʪ#Vqc9QR=io^!޺7,"yaْΘ@%$?űƌcQ$V[L'߈6Z71ĉBs۶*I[UR <ʩ(ZxAreBHiLV&bz\W eX#JN \1̈%iuwf. }mޡ‹p6OϚ=W{[I劊 dPpFV߇58p9:&eCXZn< f(j ⷶHh%o%D N5ZD`g·>0<W4L+7}|ȚHhʲ y7(;Pa"mZt%xG~C&}!I{Kkj ,`}#Ȍ1wEwuVTDD/sCchKi6`Pm;== Hz&|p1 z.\~sHz/h_9tdo?>%1ixYhU{q3<'CԢ;Mjv\OqY wSl0׀tLResWp~4 \ YL<80H;V@_iX,}] w/ͮZ8L:駭}$I}H{{|\}XYׂUbKa$Vu/4|"|Pvm( ]є"v'mD:OQUx*ƻn/@xTДGc(D"HgmWmaiw:۾a'[(y,X[smSO,,)2#g(OI6@S르)?vr+}Хr%oO&G8qD}T~ rS(ءsQ&Kwf_\9L]Հ7x۞'.لe ȳBFxpIP1x Zi}ەӱvI6~n/tw9AJtFY{zl5s)q2@=+Ϻt8= en 1suRpC1^ڛJoΟi&H2INGYP/wt1hIm 'P%fhѢ ⵟtKPz E;iCKjш9 IJ\l#ܝ }CnXfm2U1b.JٍNbHJ,2"oof6σz:Y"f z#lG]i+n~f:vN0 ~-iR4ӱ B "0,&Jj ^Ed.>lL3T3 `/0 I(ZlRq'obTK[?)om%1QjPsH=C: *׋xf4yu^R<1?[k1Д= 0w Tɬzea'{"%A"aSRܖqű{K9 S%E̚= @nwz6_57=0Iu6$[w[~=d,@eg5TM>F@Y$Y5zӖj)@Ev; M֘b[6d!BrQF A2f,x)/wĒf*0Ncǥ"s !`0{kfƷ5- dfbCoݣ6DOyS:%/Dy=:|oɂᔮ1~*F#w}4+Jj}rXo幒bNQj)_CK.OY\0̝| }xMxMI4S$Hm=`?TP¾LHIjI>oX$D-odv]Pm Lc˴ ll^n岧'!m 2 _Àw_ݏ3\{Lr:`WzNt@+Jј֡2l))!AdQlyBnca qikzז݋ڤ'\#ö"?>5Z߈`y Ij"P0mU;ٔ&]33{QCd UcgX$y7W:-,^3(z\&;Foyhvi8Go=lH~>5ZhD:|8|\oT h~x1.KAߔ9:^g Cn¸lv du4㒚)r:jʙWH=W8ϵA`Oة&᦮?f t{w7I ڷ  al!ANJ G ܫ{SbC;_NZjI0"ܹzn̈́(%lj:hnf6Q`UGGY wS7٤b~(8s`9&0T{d&$ ?7@#o*Hz6J]1dgjռjXja g%h(9[LOzz)oNt5"o>Pw w[j !uO2 62?;: xl3 b[!qJU<#U qZX0.Q *&#W"6)v9:tm\XRc= wxE0t >(ovi }i#rWJi5q btJd. 圤]aOx辸)`)y[316ějQ[|P6i})%+9фNr$Op+r8@fաwJIF\tНYle^&kb-gcn\8=!up>F:0E_d8mP|Va쮏B{=0% w&c+@gR:M1*Qc:?FGYFK"OQd P q%Q^[]S`-*ތ @"#hvUpd)lɌ{~r1BU?Ү.Pj+x~ny+C{$3u~NAm%^Iy=>Z[WMuΕYxa=D=35,ᢝ=Ł.8&Tѣh[UL9QzVd<%(`8m;!C8>,%"j4˯_9d6\4P,x EO.WV\P)ARTfwPJ%AkUTMIB>_lUp O@7bC>WXb"%t ϵHQt]-V&yS];Mzn4  | Lmċt`A8꣟9g4j  w "~PoL֊P&/DكeX0t&&jOؔ!P6cv#FپN_AjSx~AtI7=ޛ[gK}5ѨK}kPD̦(撁8hĘhM,yЭ*P[$QKPIlҰ,qDffOu^$S5W" .€qQ5C `Lvpe+ʼx0r;e32$qNOfxݴ7ļټE[9Of=yB0"4s*5K'MUw%@~ZAfN2vf벪D2!Ӛ~/Oh !Nc]T1WYԑ׷CFDxֶU\);NCy4bFU,x?{m;';"+Ϧg"UA.6ռR4(iа24^Hʿ`}FF?>*l#|LNqo /D1 =fB&Q/GA;an{7IB-Mp{Q5,-|O)D:n~_G `њS?[q+s"6n:„a1COcs3'+Cq_8=,Z QLÄ;q֗́  yaaRvSfRǹY=Kن̃]O&LNEX:r\dcIK#P5-FRl+2}%eQ<]~,M4ưCxgV 1"(}Zª\tF# ]O]&6$(nЁ <51#q< wԃ ͥ'q V;_KnEH> 5!\'r3v*mgmkCɋi:q @ఠߕtɅ'2?O p ڍ/҈^|Qe"ֽiIwH@'KÀ6bΡCRMXҰ0nXj,={U:Lxc%Q8+7S]@Bj =w9YX}Lٲ 6B!P)F=;qS,!^}PkIvJZw"zCm]Rhq, e\E[݅Gx~CB.40/X%(})X][ϤM&\ u\ps$#QӐw2fz*Oųe"c%>e3 P?YQ%"w'hR)@8^G\Wմ{U,]\P94.:MB^io[dqu|j$unVP̬$ ѣ.=papykj}ɯRMgzȳUqf$eRhW` T4/ʒ˽^pOg 5զqKf8KcRH 39R 3y_N w$\;V9xL`sȶ ̒\b 4D`x8=a4, ZXrB&XTePc"y#Q@L|tWW%r4Dg?+]2HsBHcR^2 _K<+o>4 K FFzz4Dԟx2[rQN'FIVYwMQ!y ++7_Tޒ2c|ul &b>bl'SXڵ%S4, maj^(s'-a},7@2w釺`G x6rՔ[qQѓY\X$) [ fW>$` `cāu[$GS5ѶsEg;ڜ&96Ь5Qm0k}5E1h{tpi1)i 80<4 $8^Z_8^sĊdڨl{I^UV0(8_Z&1)ŕC<>},\=o^f9 q{Əm5W9Jw"ՙumjtuEt+E}kMVNG@QฦE1k>Q*o ac^Z%sCKgY`N7c"Sl+ gd{;Imv:ۀ< %oVPM5O3GvF$\Z8(׷٧Y|֍p"JN|I~W£jn>q<r͹j& (86P{;taތ>6Ưof1B8i fݛ(:R:046V\'<cP'ghKDl$L=U TQpq__b#YPÂQBYnEFwB|sJ׏ }5 MI`?%Q3#R:xÝL専겡8;i=?Z[yɄ-M>p:q d)1/1M-ՙy\_N*A5#b%tP6.QW8yHaGprRmʀ F:ļYE#ϮDZ?~r~bi†oKwKLP \8!|~Rp:l˚V*B"2lɮ&P5A햺ʳO P\aVΓ*r~|=CYbBͣr:2y^Y SW5Z-H͠x$#%Pu©Q:)mjz8}x,:bPDz!s-C{0Dn8Vw%ȡK>ଣwJ@}y%3\ KU8Wo Pټ¦D)hQUMecg d~N-?*q HFP^*:q(f\ce˱E+´UGs8߁VmSaFNT68,SIwy7M|;?j>Qh3èI={05orJfNbǷ4KA' U2JBھ%^b,a*Ӂ$E{8ER z4  7@[Gl|SjffM0bN[KÞ!.8kO#\Yw EhkBe[ Pbr1$vlr>ڡ[h_BOR8)g^q8ʰnKqWL=c#i’B!?V=G mIib Xfk)ԮeJdWrLW;sd0VNrtdv`!$U"{g0G(2 m N`XD"Ht$3' J!>&洴 o;)S *OFT08`;d8l T66ыZSuPY*tW=rϞRϪSY ޠMgb-t3GўoS g vcpz;G|N 5v0a/Xc! ~|ۥq(8E[Vp۫eC5X4OżFVW+gO.Tv\+yTY/8j5祒eX̖Jc &a` ϼ~d|5{Adm eqǸ9N${YH?(M1#r"eOvp':%m͌Eeop(UF dW&T}b)l``* =CPIDAtW-t1ݐDO@ tS H?GTxrMBNn9Fy54.S9򁊂"SP,tT@ex B$3[ՒJWGw97/~C\EK<>a|~pljcpy&'/<3uJ9WG~@o}FEMmd:$qk7JP;穥-qR7-!{pHqTxK,퐺 TnWRyãoP8IYR@.8HIdJJ#^4p{$EX]^ws{d_} VTU{=ksK}ι!fK$Z}i_vkdB_QNz:w􄻑>%GQK{fçYc%_t,M@=Ycg ݿ)P2fRVK鯋3̢5רj1+JWTnٚ uJ,\jw/Wu!3 A=bC]^N^YA/'Fd *U&;X>sRR&oBL|"[wp:Btķf4m0 Yq>ltdm~!V(@AlE[ ӚdAqoY0+g5%J,K_ ?جLŴdh >@y0(e{,g߷1=sL" Ɔкf4?@>]B)_ƧAR ^U[-ɓq\KK)-UKjj1@Ko6# b;4o00s<GwQ%5,AX.÷:y*%R'mKK6] fJ .tn3$5BS2g|lOwhUM͹i85n :p-Nq{P6*L2~kw]dyNYDktxF㋃ ԍt$H}^e]AKXEc_'ڮΜ/Dn8܏N0efL&7&6*|,Da\Oٕ7d״'AMoA.bZqA-,/ql0CW83x-Z`QPc#jz wmO+NV4N58sUwָœp%W;9vd{AP=>WJI͈+5X9fSlMtDʡ}'BU0-Σ=|r^J3:63I D/~KA{0!+rكIZ5(w\t)O5`*MjG`fb]4*J1R'sOpq?m!Jrj璙M y@81 |.'Z@7}Lوa{>P ӠAG\lmYVu1[x%{mkO ydjA1HLdU=4 34̃>Y'5Z(8Ma\q%?*Ӹ*V"Jk,p˹-l|akյ=c~sxFU`2"4Y+eٍn 9%P:Κ+޾t̨Ez]SK};Xni=@PܡN+6X4qDNnm Tik?#|aW딗Lixl$ d*3 rC_Wj`[GQlpŻeB4Sʑ2NI`_uamԎ_(ظ]| zUn.pA:uq&!4.#[&*4Gw4» RQ,oULҜ4r1fF9pD׃h|=d70ВCSEHvfN Ff٪•=9uHYY`"-b)©=0ȣ<.M]s/;0ZB=mmK"-C  0iVJ@f]}S lhvU 6NGσs].I7Tˊe~ãɓ XEڷ7|:\LjP9]I ۡƷnqS fԳ8ߚ`˸HUv4&'ժWc*(F#F>~!^}ᲚH3~*qن4! /2Hxqf*vi?H7 at.^܎,?E}` MhbFp]{R~ ȁp(ܷǚ\UD>.yRojZxXgmFhV 9?(n=Sq. Ϻ7)^ʝ]*S8hOHx+Z@O 65>.=<h?UV$'L e;p;"A>H\9v_!`0*g@Q l,"lKԜ;aIB+q}{u$xJ.;T6_#s=cA0Cfe_I+3J L"_e<+ *_ *,OXd*oWj>1-쑺Sh#p+f7c;͆ >dҐE!797ҭH9K D!,@^X#_$9nWHڌ(a{fZxts #çx ѐ69_Xd2Hg eyڶghwe/V>Db.WtHS . }% 3OD"έ1['L~A/pb L}oV_̗nQ8J;O;۱QUb~jz79Մe2mFz]{pf+Z7U4Ns-wۘ8w2LBsעqO˽gSPa5u-a (+957?n` RJCؖV@l5eo0DS( `#6s -:O!xVS IL>2&/IҎ;\J^8~9Pfs(q*4$6ITnzͯpŷ$z#D 1\;pC'˞ aT <+TpNbi쭉Z<@SGD/[Q1=g p{P$ 7mET'$qb3R@@n * e6wõئ/%Y ,Pܠ}f*"6vgޗB,@jh+#^s;nr -5ra2q&'G;'ÂwePDied׻^AuήI!}Éc (k6fj%8HqvaCYMYשּׁ ] 6zǵGpM0-gvWg;Fjz7&mCD:+~0 ~SD \YA װc#qw蠢h/:]OTRʽ NeDp\рP[6g<Ưla*AS/# Y;^&oYnkLpZeGSEJixIrU-Q|~ւ償9 PWpLTk9: 9hy=wEm-ҴXi$'+N_rSW1^aHDȣf.m6%Kw9❖Rs[0)`[T^@ |ul|KZ,;3͂Qj}dwQ=T^ySQˏdkOɯ\prpX5y" U ?*McGim\>>%]C>9dxf{D4)$iOW+JR!҉{^&lC> q߱EpE{5Fr*3JhVߖ0RJ9*A{<ף0Vn]{@WA $[qw~"N ̃=_@9xJR=OSg5QJ> ±n=r2hSX- E}ثdZzH#-x/OiҁHfG+0]'5 ‘mm*fmO:Pg f-"TFx\%׎Ŵ_ h8= >,ɽ8IN?q'rŕW ̀-вf |؝4|1B4"J&ع[{!5~IȤR?1D :1/dFr?&b xezN/ ڐFP)'tݚcJ!hEdZO~=@S%e;''r¢4bA AmQG$ղ̓P-XzƆ?2z[w~QbY |c 峎urA9N-h,3l'nBa{1|z.HCq4XOx:-8ؼ#ՏeЏ%M\pABa[Ώ#XW E7ub'q@BDy[[:qkn#n{J"}έ@3aCO!@6VQ^-ݻ\zB*o\W$tk̩= /h]hKGK `;Yu`m_"Y9ڋ'v.N aPiG{#Z{KJπ&C=dxt1y  Z\ n?珛E=DEW 7Im?C mw( CA ki6d# n}4X*7I[Nn}0 (rF{&v,H=wgF!.+ D~hd99ߜ "^s\u[X%}>~2+Q~IBLV:a8qm:6bb܃X6zLC5DuCN1m7cG$- u/G".WӡDdV88+b٘ mjv5͍k*y.dqX^J'uZFw=p̍o`gCg֌ԙts30}<637޿>=:K#3*h-7giOJ]EZ7z6IQH6fA;+vg0GO4z8N*#BS}3NHX5,Dl9GuP :]-cNy?SEy5Etr*97F'50n}9mBܩ){0y݊1y.p+xjBЈk3%qB^v@| ӑRmPt2)bIP[r'-kI^:7MT $R~_qM.@*Cò SLōs?tY~'6e45ODf`erʯ|ƣZ$+̆t?JCܞ #5|s217Z~~_މ'qeID W,-r 9;e0dREٖJ|\4NT`9߮"ȥɽTu!nځv!A9՚Q&+L?@َiE0FA-iU&h]-`܁ ,v{ [Vic:zH&Aҿ ujXm%'Fɸzg*Dog*4BtA) ƳDm-u !c2B'@KxS&(5?Nx:_ܾAa _Q3EnV~Z*)nEO-LJ{F6|)%XflfdF;abq7O<Ub}EPqu밅PV>B 4W `KM싥ɱ!;{fYbd-D9eZ%N3ӏk̶:[&K-ii{}'\JZԌxl<mXsRZ:gΙYj9H |$nWHj ۋ[8玛kDkZ7|ՇzE#qqE~jarOYc ѱ{7,w,FC ~z!Ls% Jmz?1[RҖw#[:lT_5$s!_/Y/ׇm,?s5=@pTھBYٌ3f G9)umɡnROR"*SֵAZN" j! WS". ͻ-qgu|o3,[JnY=0h6,ն ;-ּ9d@PߙOS-X (o-Dgyv\BtNlYdLd(HڌV2R<7@ᡜW6qUFF|=/.ϻ/hGhpQ/O^P1kjUD fhtwQ m +ki}sHaHͲ cؓ.8I[4R^&^m7@ް-$dachG~~&|̰fn|'Zض8_oR/d*ٸ ).ÓታkvՂ5e`_Vy7މM r=uy~$Y8*U?'EwѴ\CŲ9 *LAQ!r ()].;P 7Tڠ,F1 ,j KVe9ZGHĈyn_h-(j8wm!QU,7OyGzpS$Xmʘn32 1`MP|uH\S꒮c`#lzkp!I[JHA͟L69(uRN1=24=e|g'5 Jʭ I ulSt'!WYK3&o:lۻPD=[tWm vp8IW[j{FH5!Ց#FrڠFM^ҏTΩŢ`܋3S%kObL_{r6 \[ é(&Ձ!)_dy}ؽ'qW꽠[ Nkf+:xk# Y95o~51Gai 0ύNao*o-@2i )\L` c(Ey)-8tR@wv>ϩdzJn۞_ '4>$q?ȥ< ?Wq-辔ҏ@V]t=mD+{L&7̃y%XLYl"' gýfJLf"TFwVr*Ik5D;S֢c<;׎?並R i{IJbD~+]-M'voӿZqn8㊢^ "~03!Vu߭dfh{ vfh#˦@tyEFϫg+_4g>D 6J0=0I'CEoR*\{Ic ?a)s7'a4j Sc hfU[87mZ/:d^/N_ydሧ?$P mmK_D:赦yݽf]aFT@`{F1ЃiQq?bL(BӘ-䞓t4pr&cV(-fpNC j߶BYDQ@ J {2(SU4~FLEK-\l½bԕaq[EZ;n?zN52)핝w8Zщf56u:Ail?/ģi~$=0~}hХdk}P8چfOU.ax]K,&;1I?|ޚ8yk{j(&zWu}\,7Ha:4n\v%{|9Peݾ6 MMM U9xd oiOhy{QƵa5IB3BAE&-s$c; %l? y{@j85la%C ?N ݋"vE%nR=-LZ9jXD7ʪf5t4|Kȡ<@i6Ԝ<{DkíLN&u*!1@wuU?S=(.T8׎!&<z(kJ3\p 7E#Q~jOQskyfvE~ ߌv(1 }E]l~]h$7p*ܥI yHTO2vhTz:퍨g.cYJK'#0$yd3=$J.8x} 7!YnU)FFOUG58%O*}C1.EB'YRAB͂Cp/6=O# +\?V {=+^pyb'M|^:;=<=}pvR)bV@V~d!wXLw1 R8)!;PZGK G K/\FMތt!pMonRNK.s8p`UCizKE;}L5zغr7SŅ$2w75{#VbMKxv}N^U[SzW$,/bnqǏ50xl+ۚ逵ˣ'8Nj9F;[Bi !ɺ!6$14Y)V6G!Lx_xKk$퇨帉^|Nx6U*f4>/%fe*ky,;AKK2+7ML*2QC`$2#Br=BJ =MĨ aV -L`ÖRau\Tb⣍|9oKo5Yp(S~K \WEK@x|Ł@Q/DAW]g'#UpC?>N7KWinxV[k3򭖻$"=ܒC8-~NIggO)ZjX4a cCµQu'_N'$/ktok#zEQ3}WvWs^h+(q?F6I0SrIɊb/ԦPW# 0f oo)S84֐$3PydVP1}Ey"SC b}A,ƅsf x`.9uzo52KeK[94XpjTyYQ+"J_JcCK[xnpt r5>4QhSHbԎ.&i!tĴ}g5F)/"٢"|T&ǁQN*BN M궧Y4hW`:(>6=2)7E\怷VD)5 BŧUht`/!\u$DaʫBy}Nd)24ι%$sn^=W%𵃣0J: ~t= w &W?| :bMjr?E[Zo%Fnl N ھ>`abbKfKKn^GH4:8> EnI7K/V?[Cq7:`X"戋 N QDYZD$SR!R|:}۞5x{[x&q1z^TW%Q B'EV2OE'!5 H/~eFp~=M O9)d(U8;s8U/vejNueGٍ]>#KO 7 HO0\3oQٷVz\V28?2{ Mk *@F2ď_(=E*dnRvM҄#Q=~ 67 /W,I_pxFLB?۱0\`GIg[!PHXn  vpM\Ѥj+ߴ; f2LRFRLHYG JPAVXm;򳅃JA [:w*wŹr*[; ENq} P`DX?A;Q,/+՘cIBHQ?q]^8|V՚;7j"Dip&7`KW)&*I!/QJ)l'ެ:rЩd]/+y  tQϻ۬؉5˭E?Y~wNb?Pw ܧF!s)SHol{i8[~n.{6{!0*;̀lv碇 ȩɔH'^K ~ le4R:t)Uu(~-tdy/D3"KB ~6Rw :`lxroۜ[sS^86Z~uX $ PyF^w=6JU܅HKDʯ'2yc~H+!AJaAS Hds* irֲTW;:MĄ8js>FF3ṹ\I)4 $&Xŗ\@Zy! Sфɹ"UHś 1F!&!N] NjC)HI ą߼yQ p~Wge['4`'3O K$愩q{ϻ/6:/@ߢX]NCQ!b)c!-}bj/Lv4VȞi=0dMi"'% &a=0S(V7^p.;ȽEg^.!R)Eu7c@#Mcj2 t"Ϸ69cVrw\v%<] WA' GDA,%&$xn7ʧ0ARdAog5x\ nب aS=P5>mZ9&vC# 3]+{c\Q~AHXtz7v92]]*2d#k\l)07}$ Sxc1'+xUܑUdrڤv}o; ) A L#SݠlJUWϱdT84|jE{f( r߯,0"`mIe]qp鍘3؀S+a0 .CO}BOۘq 1{*{b/ lqlbbqWјľi\>e̤VЊv'lRH_֜{.(Gfb+hAMvu*HΣ&Cқ)ܴI=o,B)sk9>cRiP)[N=^`$VeU O8\aSGWa63;ݚEçy]{bĞ'xgo;m1,#nвm!;r/)-5KP?jhw$ؖGFnxc1o*VX땕߱ٞ<ĺtXH$~+aEP-h|E&1MibWjr>bQ1Utgi`qrwYH1lr +*)ݲY Qk7#!3#̤Ŗ$G6"sW7I-LtnxĨnԏ9cv[_f9}$U".My,})i6狑0CSVߍVE0Xι^tV%X* LK Ұ1baR/)|sog)g\`>jodPM_}hkd,Ds:6-}OKP7qyG6eٞ n6eWBgivU@fMi#*@IHG9; TC$뤣pyyEEbRhnhρ9Cenft(&,14 SM2@JJB;[FvS8|=ygY-|Wyo @?Bv> uW4--KJ?>**SaxeM.h 7SL9n:Ÿ—Ĕ:fFӬ}OƔEMe۶{^ɿAٜM[σcBJs9vF$X}귵G!Ò_e'C'B|&y(o3Jk\)byӫ [:V_'NElHNExƭcøP|@gb6a9J3I8(DxJhx3õ }7mAf a&TxK$:&[N08SvۍG`;" {oҋ^yJہ% GUrв=of %L* ~9D%kWXŊ1j;s I$+AH2 i`_*˲LDN]N2"# #̮gܢf }oof;pIf<ôyyFԃuX";zk>x*3SRfp%v&n$m G-.kI- ~@`cRk HH03wG΍_<6-}{҂k !U~7osP~C'S|9itd2Q۬l=a#٪yaV}7)z|LF] w:Q̘uWM^rƃ_}承eG9qӅJ\qdި^<ԋoTF!S!U5S(jWSw(Q#etfu>,?:>A)s zW;_YgRi @ޙ}85{Bؼ$*^q{)4i[GO6Ŷ{FgBʲr2A @2u62j29tazLA4Dvې%mqKtAu̟礸3'4o{bՏNɺ e{gjч@_`+`ys9AY,/vq@0bTԺut:KըkCrNU J Kva~mY Kqk&d:7rs~/aI\쨺Dt8֪\{ 䫄1%vYېIZ85ThڊSF(5Lǟa=wUzNFDz ϩ:h; L iw(Iu;?2 @=afD}y@U".'1~]Lpá:^{;vz\Y\8_~u8LҾ|`!"gl|DY@m]04.2YNwb|͡䡍Ő$NaޒJ8X =x@g&B]C XƂu۪nr'G?5|f=h mto,U۴Nm&hޱGIՕaMxȦ>^횇rʤ/xKrhs\%/Q[)B6!md̍v!=x|)@f}~-|,}XKS# ?Z]b%ᢲ**oU~hRs~A":D;шBUT]b{O d[u&$jNsvy@_¤Yҳj mFxЙ*^z=BGkyl2/JTBKBH(utEAXOd"836KFK<^/ުN޴w>y( 0zI^bYV<.[Q,#h}eP)K H-3~i z^`N}uchωVc6G nQp˷\qDfL)E&0e uv^uQ 2"ۗFIh?Yr8# ]g huQbR[D'\ 4&J}4qf$~&,5GOq)Z'K9cوƯLiv(ׅ=?+\. ]%ݩN1&7]f[p G od4W:Axhchͥ*>Of﷜2HLwe | Mm`=<(ޱa@SmQJ6gLJ:o0ACBLa:fyaq͌Ĩv5n{`,!U;;_<#eu`d5 B {m֖g/򫐐Ⱦ6cmV̚qKD`7ǑݺTE?޸.}Mwej>ȦF8'UH2b38;9Mkd<uIUuqH[Acy<~=1~jbÒ|ŬJ 1z˂])bgM~1K0<Nh4߾ʅsQ~s;K>E_>Ou4)Fu~I Υ J},IJ$Yӭ1ufG*Xz>bъL$lb wITzp34 0C= } k}6+#Y%~60𺨋"mv<{ aw2`J= @(bT;=H*\ i;R$@<ɊpC816^5^IoQ6/B&ÁN}zY!FkTTnq9/p߀/|s䡿uH=y߹?V G4Ex!rSTʨ '#DiRޘ^RV1.R_0THb%c8j.OoO0ptHK' Qi@VgDԷ?Z1'NHlĀh\WVQ@n1NR-.85_  k~?z1Z>oI,%VZOP5`>üEԼWG 3(6j P*c;bݯhf)/n)EEžǮ'2ܻrPu9GUhT{왷ۋY,O@i R6nnwe5 4e֙\m|v*3[6uh>ڦXeW7r-oN p+hdxUvQ`E.n\]Y[ Uo_$`rᨻaVI9ܢ cᵃVP6de~.Hƪ9KeoPv:5L4hߋ *ק0ek$/$ %G!pQ &IԹXFȷxbwbo ˊ1;N$~Ƞ~G:-8g+=yP.DI/iMBђLEiq*ϓRܞbqeY:W9y?k:%QdW9O#CZ Koo%.E+n W 3tܪm}:2ݯP4*ּu`!cqA TJ4Twd#R1O{Q^.bאI97#?j8J/鑢!^j3/y 6MU̇rV{[~ڠJ|*L(SuDНfMuU$(~w{)dY08LfDKlhS#nps W^wŘJDiSыZ&KB!MY׍zVC5rᲃ(bցe>,_ybC!v{4止0 4f4=zju{sȶC%u_ 70OJBd>u!iM];X+ˢk{4#"'Onz;WKv>=%C'O>6Yv,A3P4^i4'뇰C$&Z5dক ftap%U#d@D}B\o;|Luv .x҅f}t=.1 dD`.]+} K~pժ>4A=%]N(>gD. ^>؂BϸT&yvq⥑NKTS@b"M`nE[9hͳ53 ZH #[`$`5RZ =J$ o Nd!i;Ө`ökQ "RPT_7Li4Qr}+vռZ;FjCbVEݴ+/t]=Zv^o@1D/-)ph\8HUn=*tAcTv7霡,٤F {?BEԊJLb^A5"WF,TRK $Eaߏa"1ns!YICݥJy__6m:\(Iqu/ lRboJ ޣ`PRCo* A4c3"MG`qD}DڌNx +p#,MmJ 3jZts~6q8F){սE^b:h͚K\0WSf 1LJlJܿo˻i֦c?*_/\)({Y~W?' R"?%mQ~/ņr_KɦK9/vÌ{Fم!+kZ)`:ƜJ}{r}Fr^֛tVYL O6^ךtBdօQIC,[Ivi_DX~<9' ;!;ҁkr.>H}׮Lz ^i^RN;U2fPowJ%:2pɼIϝY_1$R "J;5}O?"ɹ{ =V1_Q?#N7~ȅskgÅ1>tˠuÓ\ eDS1š]?ØW X0G<+Ua֣d3kӖU+oͿ۝ER3}zPj "="2 /Ik@Ib9\`U' GGnK+e13ߧzޝPW=P?yoD+'F$$HpX#}ANKIO'%jRu<]HppoE|#ڙCW273j3E\Zi|[nTeW]bwOķXZIRLྌCfQ`GlXsMCao9hgxwVdZފ ڈҋ!W!FS|O|wr)3doqa<ϱ}Zv-YiƩT@\{L::ۜrplozt@%&#@!xJIuh8[iUą?4.r~ߟ vYp{?9j 7(ٖMr]`,rl|0EVh+*0n &ԧQd%\ʆUͤv0? K Ѯ1%RGyɻ씝xȍx8JO2\Ο~SB^nNhPKę=Qb9\&9#<Ԉ „WwDY_4dP0`6w"uPw)+T+PY:r>6KuS8qǽǣ獻yr!wmaDb,N #J@| Nzp6l-]T5|qyU h>IH}_k e]MBvE^$ XԦΗ"^y5M 2Rgp66pC R '0+z `_Z.4. RZA9F0K`(r-lЌ?Q2F:Y w#|-So.5%TV\o9({7ة'=p+7A,'PY}4[0@9H{nn{\q`Aʣy9Nz,1;o ф,fQc[E[#dw!-B!ΐXD=c<@6KZijQAPRavZVP_R(DZ'dcp5ny ƜZhBzJ*7ɋi1*tBY z+t{x1*peb?Ӆ@Slu40*5KR5z'O4dGG*>镞x!C̲n9Y&4ۤ0n 6l; ! }Wc_5T^hrr>}TRiɀ*-W 8A= t;E0mι<!uf°JJS]?樕# eozD% |=Ba3$R,׷3b%5u/@AQټSFA Hz 1~ހqr]SD*o4),YAfbU=]+=^κ'ڈU``ΉZ9 ee)厱,qwB ɒ.UM$+zbùw5]T.爛f 86N3ݛLTT [Xq9r=u}ĵw= re-BkEKvO0>t&4E6~'%u xxsl{f"ȆL95v= @H(%<hGlZ|.Ýt5& П! ׅ/0>)'nL}>Z p|vk/b|,'\=4c%g VM9ႜ@fB bT5UKfVtxM˸&b)P1V9X@g:lP'rgfՒc&3O`e#2)[9;[KJIHjVӚ;I>;>]z?CB/e_q~{HRJR'~NZ8])J6tN]eNϚ?<#bRkcG)X\)3 a yzHL8gG]r'i1az?=cM>2<+wN]ҫCR{j*A&w| KKpGu%&#۶ݫMpۖ=@rM (6㿟p *Cȧ1{`%\O<.MF]eY/ok#`Z{?FLIh/?7ru̯nyڸS=*Ƹ?Wq+W7LGd`ԇM˥C˅s]`Y?لs_[y#?&$rw] uV[ocyz"XưX&ĐA-cEy^YIz c==3oU>KV34_{bdhⅉ1(I|8`CŽ d()ׄ6k_4w9i!cP*H6Gq'rI5uvoKQmT<9GXHsj:Ro\B*ovYEq G~2hA4t M^va #rӣq !>^~kH*(sƶ/GqӱGi-P3ݤ*OvDgd90:#E TNI ; Y_b?@YG-TH-lΐe5,2|6\7ׯ:]Qԥ9ŔWN/eBLR@bSm[c }.X,.T^Z\ yVxiMJ!+E9:7 %-o/)()1IҺEf%m+,.ۧ#ݙ1Ewu2o UsGoE1ucm] (lɳ_¡G"&I|2Btk=g%(\b1ᅦ4?Yy+-לiJ(}z"aZKyMPp]md<Yek3x kv-g8F퉦6-&^vSg(\|ć=O;WoY3307|b<6 <ܓK>d RΎR⓫­4|?'\S%d{8*uu׫H|FhTD `]i+H)2bLh\T(OP?4zЗmڮvcQ揖C ʲ2?1p ?G*d%"eVtDɗo jk#C5P['dRPjeUY@BjU'^=66/܏lHjxT=9; -:[Z$|V h}7|nn8ʬDgfn?vM[[N|>&9^ M'&-'}H6K= Va4*M*\J3 L֨~g1'~MG,wcfߵVE/?0A ut'Q[@S^TkLoKO>^AT@$ !,) Σs^q~aNr E~ Bǐ't3 Smu%[-0h36G0pO| __Q9(޿u܀do RM{k2<^$!֣^o X2^Tǫ0 z` MhHP g61+ddzIa/~ćXtPE~Hb-5i`v琠C⫛prGfxƃ>2-Rݹq:MC|(mz(()' ;tQVO\m%'Ss(hbÑFa{7k )n65_X3$yMe4`!TaGʫ}M9uUW+5lh#\(Ȭ279'[iqqA*TzںAwј[0S1w.hz|M/j_& Y'gEk `j8ъÝK%(ͿRIbeiXnO@Nd!9Ԃl;;#uwԍDVM(H\B,Mh b @ORڃR``: gF˯ +jR},!D'@_uuLq=.i|@ i?&Bψ,vEp&"{p!@f6BVf*+Iq F@8Jt͹F|&96y $i(W@=vmHhu-E$arjO$êǷgp3L/0fL WeՓJP0 Bx[@}\뒢Gˣ5>S;m^sw8u{g|)+2b~E[cT'Yn [o۬VSHݪ|+'rRJz:x{56hh7HѤiy@d^::uLUEcd=">|EU%k(t S`-ȃRQ.1TPg} )P((B4K6Vwtԅ&"32:D vvo<_";vK #hI[sG1Ugd50~z^۾1{n)AWB@}xRnDBeޅD7WF/EZ;*-/_𾄳dqE$VPu<|ôӌ&|.Y«^ָR8Ka\=~TO3fgmtK^`Ԥd aK@#Yڹ2g%#fO! r.9 HGM-L7db @"?SL\w^l쵈qD)cx"B4(YtȢC|k0 );Ӟ+a[m$0ܚ^KvWlE"/*a7y!)֣Nflk͇cׇDo2(/~1Ͼ*t!8&/Pg6$kX lWGA0 [*=@ p};SJץGbm\kй&1luNyEM 1"ML e'Vܖjq+=Tikܕ HEBrvmSW!c<Х>ցj=o1dEA/BƷ&\ͺRN˹1&; tRWi:Nί$[- *?2X ¶-=|vJ݈׈nL.BSŝ:ԗW-dP! .ʀ! hP H[R3|y $/e*rMg4G<7-vek$7%@@v,޾yue7})HbL?8f4 vѭCZaHiM|3iHP|9v|E^)?Dnmsӯ،d a䯰#E+| L, @p Ij7>f4g?W B;Q3- PT`~Iaua3\{ݗ-zXhkqM/95?Y*G/?'9.XXhj, JW;%j|]܄0c }CwW!4(*1 7,~c7(b8Q;zn/HFCLMVi*(v[|f$/U<6 vg4P@?Vj73y9:5эcvJάn.sl:'_%t<`;wk3+p뇴{|̛Il?:TPGay[U{u$z&Lxt}5p3JqK0 r蛁&,Ȑ2NKoeƷGl< VunWmhk¿^ؤ@G(sHϧ1<g^]WTYzn@r&q! I68"Lj'Ӧ+H=˳H ~ڼ%f 5H #s'(rAh`MjBv=]ZSdxoDMF\2@N5ѪۤC^:%{ޖLT83 2o'yJs,'ĭN6 kG1001 R@Sc*zLZ;}c@3MQ$̓ZhH &UēDlظk0~^,1MK5*\[#տoa$':gL=%SB}@]WW%bd`Xh>*RD70c 4/ se< y b)eO]BK+Y/'h tU<+K"T:!a_Rw!|OE5AIlk`h6vDޒ'::ҹ2VsiqK-j/57yr#en cq4 zGh8DE# 쐉:[J= z 9P ['}l q#n*FDBÔAzUY[ͨ5Tubx;[QGlM|A8_dCKkrd+44n,&r%dbDqv32`Ӡ4f Aqݝ Cgo –޳' 9ļ:D2Rb[(0m2~7Z?=)-9 B{^ƐN{Ky _/*h@ny`%|qfH=Ϩ堝n yvRE;vo,@& ۲qRx`-?O!0Y(K 1RڋZ{maBI"cU'H n,1]ƼޮeLXf1}lÄx`};?~JVg 1)u$3dx;ܗ7-T6ԋ']0P6hUo,^6z\ 7*Mf 8 mt7XBKHڌ o[ ғWKk0j 53DuRe5ˁk7П> ub*P_LOK"il;Wc5\*[<>q (_o`\mVS S<r<1$T:UZTOzv:=Szlk&a/K=#nFAp.W:; &wgp aezmפU_ӄґ8ۍƿ F !N񀌃:`So'ׁ$v$wM7y8Nnn(JBnly%.CIii#E1랠vvx[FnSQԅ%QLx(iԕ'ij~!"d ]` HrrZGΐ_o7l^ajV&P K5.ːM !*1MOR(I&kAd\.?;WEXN_Gx1ȽocUXEuց;b#+tM4(G=ꅴ.AU֮{je N$Y{iwa'awsŲ wڒV`@Y.eR7;݄б7Nt/M#Y4Vp6EF Hd Š|w{[ r|dMhJw7? ՆҊG=$E )6/Gb۬$gf98l;zAf_,켿Ddn*)jn5u[msW}8`]5 pGf׶ 457ccD;nH,CsB|ٱ(ݚքI% c֒;n[/]`"/<5xxt&T/\dms'bkU!o0C&DtNZ)澓YQ}3MHDMyD!Q"2!/cVÚCU;E0%pUz_@ՊkۄSސ}F#$AJ@B<2.ɂwx槎'-4Hr)G'(LʶꢍE V&%-2ztMwFρeV F#dl2 sI|5Yto-SoZF jЄ*i+ -SJ" SS<+_l[Lwdx&?nnĴ=ᖒ3D]P,:d@bFzx\jUgw Tk~XQopQ!D=kF|v*ϋ0k5_oIyZ479Mth6n57*M\<6o^]AmAQen|RR攽\ocLw9^3}Pnzb1z2YE#þsV+}5 -LMKTx&V qP.yklTYSp#gLڍSDZlEۍRw7R]u)x|:@RnGB1,c,D.J15r5[axί;[HKSN$]gwq+ef''Ash46C ai*}$&/%9c/5XSYoW/&?uêg9\0\s pTNkҕN0"8q6UZhI@Fzqowy: MbFS1qhh=@t NFA~DX#>a]#3OH) Ͻa} 0wdZ~Qnh`7J%"}H)?gs|sNO+9gX=O*JFRk; `O߭E3_&aVbucOp?YfMq7G*pѭ|]'BM)fEI\6}铫5^]|%F߉iҟ}W(!8`[~{f* B?m4pڠ2dP~M'C whv"I^3p!g%D|+áF(KG@⭨?gK_/m)eI ՙ[/>0OrΘ5=/*DVҏr\P_ [F?dWqdF8AMhhV( /lfTEKL7P[8Ԫ%Ȭn<=7ECcH<7ͮ1?[r6žWme:n$e"ʗI26;NC4DyQ"E⬈7??vY șiB}6kox_ ]<6:s>d*@=F&"Ď_~Xt$?{KI1+,B%Rs`||8ihl9}P+|A$[3?J 5ۻ_~^Qc~˔~Xo)) 2,h8(a0XCMJe vGJ1]"B=L?D$aw]dn$K6KK@GWz(a­`_ V̧ǒYizQYpxGŏWwyOFfCنwI富P 7b(DH74iҕSUvp8mlpsk^(ZyʹX7WhA~!0n}F.ͅrVOs?#뇦R異j~燕: Nz03q5yк\$?#Üj?ZIWkb m$ʳ;]"m P\4Gs-2aZs %ǭ*Dp?`ƣ7i66ղ@E{^ ap,̓jq}%%50WCRƱK:$)ͭu[2Z>;.AdP\& Ȃ!+BH6_Ke8fFw:Ysm0aÓh.(!Po &438VhFb(\fC)Kuzg@1cP/*m&4.J38! ak& =w"#smy dm@cRm[{Ć[^W4vuʢ߰'ˆa/*f^[`2韙"2:+ӷ-`W~/Ar=?BXV7#4))uo(O1|E'|O?k!]vl%Ph3YM4Y⚵Pa#$ yi>ֿ* J17wg ƂVo5CE\ȳ܏#[%313ŕٰ/ĨI ya]>s @ JEu+2fop('ԻH35euAjuVַnQp}E+M=^E l aB^3E F.NzڟivMù:[I/tD+ %p۷#zuyK ])mA[$vPUSzk5zONj=!*Lۙ9]2b_1p̅](89\{|M`P>^_躺;%eB|fvK/9a"u~%AI_^^`FxV13 1g j}"' yf*؋TŔ޻ 8VB&D$_Ŀ5&|}-ft9OQY)!IGo:FʆmX ަ^ٗi)˻, ,sNjaBp7WvЊPKsnFj_[}T @V%Z5Ƅ9aNXPXhʘJJCqŭ0q*HrWqǿeRײ4%!* XTu$L%ķU7/1 Z(c/hh ?Tϩ*0>4T@{ {NDV|Լl&ybb#>R!ПU2Bp*QDe<ɺlQat?`]%MUs,y^rd;.hڤrBNaC?ZŚer8;XzGFz|b^|ɶ}"#9 Z=aAn#)KuuUcLovڪb 뼶 ,ڍ"8w:]O8x @Y/G—>T3zENA'yQU5kDd RwƷg~.j4ӦA˝<`&fO.3p(^{sYK{mb̖Lt+ċqXyt2٧@?EHAn38`v ~Ly}*CG>3=va.-YArDtwPrrҴO?K*g7[8J>Q{zA3[F>F7 ,QtYV.KFQUΤa9v4m!{Sҏ`Z)^ˉ9?[-HIJ+,#d4@>BVgw,QվQ&Sz}-P̡5}AwTaa{,*r>4i}鶪joT?:ژhb͝d7W7i9j4qwN}W4(NKlXA4 \@J0 UsZ7N0Zep $ճ=.}{\{mJZ&范 QP1=S䕆d1P'FaΥ .a6'v?TTg9v(6!33>5p>U(zxЈ&uxY)]N8waIɪ{ JO(xʑ)+ԘQUD_\2|8/p<]|`KwEްi;?rE.}9]N(Y2D2ƀBJ.5rˮeqE"2efs@ʧ pՍ2pLB'X49SGN0qFb7Ʌܾf[y'1_S;c:{#Lŗ)>[^ pRj&e M83]cnw!YmqM 9h_x|@ :ja^:+#ǧ;=Psbn "B_P{</PJ R$HTy2x뗞TEo5K8~=+K͒ߵ@;L{%C^0d+)o+YZ U({&u eK5o[\ (jH&r]Gh7U_ik0QʪB^vQkkȴ lpdB}ޘʛ EKQ2B=3}-)x%(`HgaRY VJXkpgM[m||MJI Q<Ǎy|tTw9mkmNPXP.ד%E5p!p,^0A ;I{I}IzB w`L>V4K/d3d6D+;&i_xN"_W]A_vY8 a't/Т"ޓ E5D6vZNn&g@xz(_L^=+oSJ[ dт=ed2ƒ Aز=.h"9p'+iM0N'tױUWӢe)YGVq/59v_n |֊.aA:{X2a/aّ!َ(< h^s ~X^!qK3i<9yUS6V;H3,޼= ;[&]\Qxu jcPXk߷rm\M㬅Ȳ _wLYYN*vįȷ_* R(&f :\M4N.-<3h; cd*=Nv PRc@0ultuUf =@T20\JKP2Q5kNyD-TJ zM_ž(Xr'W؈YLm|TEptNG@hÇÎfR !Fd|}hΫY,*t+gSȄJ^% foUpS7H0?ϨM$~aV,m'M\k U6 WTD}E'\0p5q8GqKAiLHKthpn;}VK ӞAp,{mJ!ݵy&KD1!7e/,2:N 9ڏwAeL!̟UF?“ f+Q]Ϛv`sBωJ;-ďSEc<9Ch@r Azmz^T!4Zn[ ZGJe޶Z5)L3<#c`B{>gͥCn=qx(L2dXCpˏ,aUJd}t*;a(֎$-uLk|[`wشuݤ(R&hGw1N{w婹=朷6c 8߰) »D&oJ[{c_pyw_.wIef( pᯣ"wMdhZD CzOs~/=Cc>4}wU b(P}gSuHvYI?^łP)ׁpp_1^x<٦1c<Ȕmk-;Ӽ;~ p4'v8 pl媸ܩ%A_k,aa>% [b}d,ͮK8+<=5 k[ÖK: *EЩ6#`'K0"ܦ#3HX L@ej#cULЦ&i9ؠŒ ={onD_8u%ARo;囖&^,}6@Ne"6,fi;Qꡠ ZDZoiܪRk2J#WNBTlH{S'iKCd(+uYsQIݥzjYO3q}TՇ:;ʞ> w#JPn]Lzyҍʬ}\>ֽ1 nQ$d&X.Aq';pg `@2yNSIP$APA~r2[ RP#`˖HTRț QBf92'ki4)f-G1jäQB{  E‘.-~\o$N⣩Nџp8Xˈ:jf0eS4?Goɻ,ϓ{1^7]|s7"L [bS֥O>H(Z2jj>*bQfCPw>*BL~X_S Kku(UOa%{H5y 7G`pur8?ADdͳڞ[j>{AgJsh.U%@N2젂7eh6DU'+J! ì`lR$QE`ޑt<uRxӓmx <] +71' VH9l8,l^h~('J @?!W'kb叺>\-lutIя[@ #ofv5TcX1H*jWɂ /\g;4)ejFov!*oRO%^?4!̱zCX +<"g}6P~Ŏr"`鉢X U>G0s5Wy.m=)!3v9ÏM1[_h@IՍ%lD R&T-=#V1? -$eE@bC\3xbA?ń;Tj>G ARnlMV QD N2Hj1*pqpoxp!@Hhcc>9+%)Ro/'jNيӢۑy.v+Ѳ,xyQd6(ٻE LvY(6GqB 2b ˢbkees3йDBTט84T٪Qƛ'PcZ Wχ{9ΜIYƟ]Z"r'{n -2wrWa i2Ax.1ë^\q s)_yFdz#)K0颈JBnU`ҟ/{"|"Ғ&*[;صR:)왪:7;҄)K% 4\vjϏXׂUʓrGUD"Syx %-HK|#IQ(yQ@E6g$N&%PshT1V:#Pls;6_>ߕwht x 3Q \H9Ř3~V`0tǑSYPG^ˬK(%<5,1ih"" ޢ :Z-7;L*e`P܂r|Ǹ@UN|G\sէ'I$66K }_ wJ/0=*G5X<6ԛTBrI_@obG$D]Şf-XO7:\%N?ȮΉBoܓ<׷,d%٫}LW90#)i :3,(dX@Mf J[I$gz;WOtk$o'0ą`m ܈z$CCucCGWX5}$a&m`3PZM_&ՖnK2Kk otc]sst[kNh.S3‘nUGya7w $8"thtq $MFD+ʐhh*Y?o-W3p : gRJ2A[U}B+vZec!Eϰ|N-ݎvvZ$G_w;L8abh.ЅTI\\t8c9h`0@\ҋ*^g*ڒPV.B[ǩ-D[SVTH2gFw\7Ofč]|L^{P9 4ss Tx {w4_s(zFVxFf#)pk ,Dd#G֞ޝ$ >̤0DV+M v< PίLlj|Z ¼h+90yG_cktn3\$xqeu>s\ EޗhgP.s` UxUvxAb#"X@=#v:x>mg?^'nՐfaivx` BhrLa4(:!I=0K+hOHCj*HIx)]-j±h nʨHN5w_Kdt@YVoO\&#}XJSU~KF݅+EGEfM5Gy>oY*+$Zy5Ԋ;6z"I0,tljl{b5GoLFh >]H8V7d%G&+O4t+h,S]Yka$WxBRb8zYk.!$Bkk`gjQԜk}h l&%O}Lw|;0 ?n}{3X;CG 8V{Lue\r 2QZ;hZzvq.1-4 gݾ ,1@W{h@MZ,6U 3i9@oUލ7B.;cmeh}KPOeSlam0m^#1k^6Fx^d,Q/W.3n` Z'ΉN -FVHdz EN2r#?hP gf , GU3t[yVٟCג+m%Ѫx_2F{eMSA R@z*J~Dh/{ŝ ٩bZnE_:T4Z'u*. VX:4iYV~\rT0~~1iYb#xp ?qB}3"4};Ǔ>icUB&d3}LcX 2kS1?V3-/kY-X<6 4UYrL}$XwNU g3F>]PjyHm*C "B@UZi ѡ/}0.vr/CFuOI%60}>KPoMDnqx6hox!;B,c%Vhdy"Ğֳ5^y}cVB2S,6;x)kfO`Njӧ6I> VA?P1ZRJdE1c]'#>G܏ Gb{x.>! I}|kkb\=P3SɫGe㶎,YIg$^ R1Q/I&5=W[b n7Ș@RO'2a s'B}x45PLDH']F:Yq S||͒  zx1,\A7_Sq 1 ɤ 2./>(X; \(I]>XsVn-g"mm0T ht@ u4 u2\1,ihnLAL?X%ȟQQ cs2jU0V jc%Y.ڸyza&H mPhs_u\0ܭBElK@±Νhq6̝6RI;޹Ԧ.V[f(H~{@Jjei!_yWI-n,aGǔ0 'z!e<';5pcA 6a|ڙɟŞLA:U.'ܲ2+KQn&&ʞT^>׃PUJtzVxS8 )=1fojʴL-:iZ9n6/ ({ M\攆N0P%]._ۿ;8̂pO0VLTۼ!/C]!GD<=A0Pcb 02{q@ٸdiS OY5A8P:u#~{2U'#t IB-|a~q8 }2iY[˄:_ɚ8wwǖ)!N-ctRݘ +*4 KL6Lre<)HD獕KCS'Q5qoh(^ɄzRPĔۘdYT/T2#_ {[H,h۫ke ïC!Gco[e%EW]X&$?򦢽 -µ?gi'sgKOuA2t_W`(7nP@cvd3%0Vv !q.AZt}zdGԑteŢ+^vkM  ZK EElڑ-N}C!JUIQ]}t9LtS%gl{l(6$Ή̝tۤ15m쎌^(S+ иcN)"!As8#T!>P _zb},9jwLA+xi/عr8| ]`"w ,(ER SgU)6{}{ aQTxr8^2$kKB@J.橞 PFѯNU*6+rVzexShn \^ #*U¿, V(BI?ݮjD%8u)GwU_D xa[~MF$f4bMLUAx6* q42W3=䒰Ł 8ntʰ-I#Ad-!])V5W 1sfiƗOى6Dz^,QY0*qʜ#0ڛA`b Hmg֥,Hhs7:O/炦{ 5!HjmtA('vR渚jbTӐw' nav5f[�كഡ*ŗ`ks" '2G"ɮ bDDrf|pCOt mYv'Tیv+j=5!TaGk(X 2z_ u#` !E% 3s`! 8[ƅ`wO'Iu2?9Y .z~N7וUa"r_NXr%uhDee>xQA86kE1:DGaox99 ^ 6̀Zӕa2 >F>,+)3]Y\3+H$'ߠjֵ4֍H,qK)/1dy- 78uiwxbpG4è508i|UMS>v#CUǰu1}1Vs=Rq7iLLLD W< ~qlp#8qYZj>\{{֕:o.˦N2SmұّvMnt Uؿ&g ʩX8G {m`Q8InB<9#pJXl+CU҅YF&峓 (qOZ΍',.t:L["CM<_>/da LjL,SjST%2Z7]$hMq3ze ~qR* i0vN4aɔikK-݄+.zCqYIN=oqxZC.t w&߁Wh/k!G+2x ݓITK ( /NưkCWE̺ey}T ѥ%ő'=y$uS J~vLTS>t|ҋ *rrP:j";p-`#'n2?C::e[}Sդ˱Wt0!V >/0QMÍ4N#%@PxX\@S-4!̈́}%5 Ec5a?-~1g[ 3F6Hx}0W-x`d/R[&"soR>.a.I` jg7ܨ+UL)yjΐbeje\^dآ9sǝ=䪛Mjw@A=C3V&gN>#9DBm|p EE33&^'d#ի.g~FVҦGB2uEId#* x*뺔VQ.ϖAV]LX۳׃0d$wW*[𚇞: T j*s1W:48BV~d4O _1t(BslHf|~.!*h. Uxjh 5FYJna]ek""=qL1/QtAp&`h> _WMqGvɄ8X<8ڢNj7>No{نW"FQeZKWwe#ٵ _7L8d܀iQh7 'ڙ9" otFLfH2Zc?nSԟpZh<|rINMk\p6e Yƴ7c1rozn52cB"9-@(>j4b+y )fͶPGmy!Qis8 \Oeo =cٶxueT{ (-*ǗM{1fݱF^&~h3B٧3uk࢏ hy?нfn. -xUլ }[B d׺T_Ϫ:.%-0qҩ 5FEjj$y*mʌtnbsc@0Un8͉nfO:l Me5LXO&kцc0X?e4m*ItM2ZeU3<:C܁TuĺZՅ#.Fsuj^:ۭRW0u-z!qt踫Y@Ez4|ْ=5{^On;8^0lDO>BQ%^kԅol7i즫>?rGS?hgn #WRh;9 dt[OIe"T{s1s,OmpO9(o%9nNTK1N[}k㆒ Vs%_S9ťip[\Z~"ERȌQ{*8S90졫_!tjKpY|+!(T~.ApSȬ$H^A%+zAc %:WQZҕ !ckTkj үPbv&|m1Fp~@A3 Dt^Y+!^EbL҇(nh16ώt!,([jvv>*DQL}}[5nw$!cÚJ .!)(nԱGߘvk9.АG_󥣤[@)3M!1h)>`7o:cfCHZ:BK-*7?:ouzV ҪP)E ST6;H,ٿx}xaidIָ- DbiՑ4O I}{EP|汖}!(uƘ >Dp!o"2 Zr @Fb,AKf)GŸ67L/>EH烋2/V"LIl~Ց+#ì{-_Y_>;@e&# h7՚?ʔxzC㔲75F 5/mA8lQN*kرk L EؽC莻IϪ u5DSI6l%B}M P_=/F:J _ ^EL_k&gn^+*:~~5guƁ@yԹxK>09'1O:$piaxһ::}k@bVBS N'iT%vlqFk^/x_L!^{?Ũ!!R:+Os[/uPQOv"t`c@#^NJWwy~3A7BCYKd.](To5|)EWS0K?d$,!@dbꟷt;_(^X\=SAxsr̭[2 i%c烙 |2.gMf]8Vg97#HJF᎜sEmwIMLa65 A8qD%?I9}S:"#p\wM#ZEwX$112aG{/K"(Qy>XD~:bx"kz.+G MЃ3I0J %38h7Jl@]ŷ{<~΂: lE`[NC, &[ԇpp,6?cM֣t{àUtbT; Bƺ-'jrE0D4{?tƱΗ3 r\AV/zlk|c>lp9=4ӑACg[FFb锼p /4g>g v $!Oq̂)-9bǠ$փ|Xe0YH_V43. \x9@=nR5j!!σ Qt^ҧqyJon N IREMe&'׊ yny|)P48 }'@vPtYAU,}2oTБk+QKw1GSy0$1Krir OA<ŵeIb>\@eF#:R- Kv+nHb lH.F9#&n~đZ.Vp@R\XBXQAo+f8NNkFyڈɲt+4{ڏ\l'mS f5\ZZ!c_s]v-T:L`m6zogKgc-ׯbY$v@< ED.TvWY|;0a"Xϩ0SlguN?6xik05w$h^P%Wu \}+{yQ#!3N*g= QҵŃʌ0{En&ӏUÔA(S^=Hm3!LqᨼJl~IK-(꭛hqӾ4̾L&[ŀ;&Oc[hPE*dV8!ŋ_Tu—mIL~^' 6$+yZPE|w}tXɼ c_lҷ(kVr 5}>a vk40ד*FSFww&%Y1Ih[:h>?8L ;ȔSÃe9{҆Z8Orp#AXZwz%VlCv']BX'KP?e t^6oLMlD͹Haɞr)S g ##(X[uPKooRZT h4<3ƀKdR!L'Q] Ot 8u3fkWϩ5Q13|ux`JpkJ(EZf+zkrm'?Gnkoɰ#Ⴡ1\I4)-t0@ܑ\ƎQly˒z5D䓈@#ԗ\G1e`-_qn. yvZoVX +C[)JX1ΕN (xTgz=aMxC;]7wûLTȒzhVdŌ0#|2vH͘#LRwlG,2J([lP񩪺+T.;9̽P!D\;7*CP/w׮J̤dRYӿ9@g0w4Ni/ -dgu$*v oXbQ*y;$74?=s,kat{FA.w(. #`B=Q#< Nx4dsTB2* ,Y+ -ܶ;q_<ʛmSayY&zmp{-0*'A#{jU{[+ܢjp4|U V?d%d-*L5R^_k&,y4$x^8. ;6>CБz#G~/pZX yd{Fxڮ&q[6!!] ='ηH 7; &Fl-fF)* #]9A:M̦M4B-,m3np^/mNO$#W _BA?;D:Aw_w5e2փG`GZ1wܟ@68:nC=KaX)1A_ )>1q>; OPSP{^"árl=@8}=:Uq_x i?6F3[F0 | bmFH {rWU l'=aFR)TETgJO I3 m-xE>K9oݪ=D9Io#~p&oaYV jPBcuteߘz}&і;KE\EۊY]6g%Xtbc(_f-N4?fssKOE{U1];*Xה{QǖdC0 ^k|cߔVBۛexCjd}ЬE"D>_Qv'Q2Ήq"{v|5*65('Ii_HCD^1#}Xl?(/8R$KtvXe%yVa}{~ƟkkyA>۬PX9TL6<&(eg"3!+n9ѴZ% yf OP1 B Th(s SmF6=m,FwtJ˝bᮒ6eH. [V)IjgEd5R r ʒ# M2J,-DUyѸlvm{cTB% F-TϢsFf@TW CX,֔r|/7L1a+;#\. ]&yŖK0wW`M)jz*h4x$㹷{B?<ڀ5H aq@n:2/A>lً=pt n!@_7?SIͨakD!rpv4 Cp)ﮠK>r= *PSbl8t@KӸa_+I6t'm@}etۧ0#4`0?8ATJzGG&&A&,Uc 9Iչ%#K8f&!.4Eʆ ;~ s2Q:v?Gy+ ^ f7E2{{ǯCB弖Qÿ1GGjag-tլ_f9r"4H8*.@ .g2圿I1ό!DSFG΋.ԫ_u ֭u?sNjÐd 3EO*({B&,'ƃ/ 5j-[N]Y#se V!Igm>@TVPoD1dL7(QnKL:G )Vr/xhoMp ,5FBdkz5q x'qi{}AnXKlfd0hpIi71.못˃_<0FkZR~-l FIl'Z_RrtnyuzbZP<ІhuF9lw\xh3+܏cO88Хw(~ *_y\H֌`大!N{b{sc$Z [rL1L=׶Mɏ5a/mQ_^ Xv7Gj\Web)L %&"PV7>=ڰ+7*fwFt)F|qeE]d}ntF(ˡE 2 VqǃA[=&|m"eG8RyV^ v3,!q1$8p|(_wO;8\lD*^ vq@zAXi:E]i*j\,<n t .)C 5XMɡfݠ®ښҮDzv< Gے'5$Jf.}#!QB !:L>L-9ao4LE꿎ȣx^65)\Qlx$vbRDTvݸT M=)&F>%4bhkД{wȯ ,=M/]aMӁ-ES|kkʖeo˶'w+\?3ܯ=G7ӱ\2mU<)'0zrRx *Ug];mFi΁_;p&Hŧx (HI0 $ }8!o,|AzgynY6X()æ@Zx'8h4{%Vnogp;). d ^bv LG9[aK)m;m@*ԜHBUﺤ?}t_yX bIS7#0O95m2 TΛ,y@QIwuӛxuC#,@qVH !+ $,b@5=7l)\ʧ48HOd\HJMe+;M7[/Y!gi9^V0Y.uCh/GV6 ,9ADˎNo*H :եcf̀$pWyp~I/&8߫845DrɰY3J?dsJǤa2 .k2ZtV.Zׂ^u rO)%XK#k8mp}$!Q7 XjԬ_ <-S3Tc Y0n2Z\ɵL~'[i}/$ +!g"n`o,Igؗ\fCG9G2oqovf]Eu9ju-sƑBՃm{4@k"nwIg@ G E` ohfyaQR⒳Miuz/Ԃ#ҹD'4~,v\k^4˻Z˗lSՀ?ͪ@Ц_|||VW(#IeC-+ﰶGTZ hbB گd밄iBʲ9o24L뙣]`b+`5vۅ6>rP9Aɥ=C֕aflfo~(;kRPF}_)M4pkzFnlE”tEyϴ-4 y+ʒ1l/ٙ~ to y j UrBgBߝ^ܤ6niyqxX}trdU>HԦWPN=aqAyx[X 5W`I wA'(GJ<$z\vV%oߏA_p *L}\Q\;I g"1g~LT 0 VC&V`kx. s"H Tw~o,U%,D;*~֙$4Umoz D {>wS8TwlU}ʸq( .˕#TxY)q(7r:MT٭c9C. qѐg=~@2W_#nF8u]Wr]1+S9-E! w[khdB˪g } NJuQETtldɱFQJ^C,AAWJk.h&<25ϜDev=cNܴFpHo)>₻CȐFȶ* gX9o 7\2s;vqDR.[,eh9Qt(-c ˙.ֹbj噕YdP? c,X3|tc.դ<N-JGmc=Z$QѩM=eNNcpCxB{$y("$}"N)OGFQ7 }G{07_yI 3ᯃԲ'4#Li(zz++7ۻ$7m/PikdGohqU,Q,]l׾+g!鼐'-^k0Y! W!_i:PpDAV,m8/O(cxrkmQ(wBx g\~udY3Ptp6J%ϳ-? v z񉶛[O}$TɋYϰs2M4K:3zJ;M"`!Ҿ\q|fWfu$OS0Xq NNܙ36n$lr`M9?ǭGb@gw1g.L$bC1qtaxUnP|-zXeEe ƌ˹ELM$w.v9k! j^iw5`$ LGQc\Tu7d8#~:E ,g^ted< "7:)o1A KVZ?i.ǧK)JDNGRv"!n621etەM19`u3|rJP+ aZCȵ5;_"2CJg:5a+_&q z\>,X 4mH (ZٶOM׷N}ϞbKyL RH6_mTʏO P"PCݛwE/=lriBN~hV FP$!\ 4c=q^ rw$ E"`^VsMfGM|4 GXe65N"j#AT$Z kxq,@ Ϣb2vܖw".QvY1#,bp|6U=:IVDZ_4)Wo~a>vDIׁ4/ȼH ]J&$ OwfVK3`#e'IIL)%bDtJ>}95-rԈv=9ޘCY'0}?f@"?xpo[]AZ4̚u>ǰ/_`AOf6(fgz[m$%1R X=Eg_[|)=ª'rwDR˵4i5#˟5ܼHKJ q*cl@;AkV 3ҷ2_z+cQ]&u⓬(WL"̪6hQˡY x)\=ə8$QL%$&&>8o?J~DaSŮ`8 d~-uЉ6tދ/r{)GBqtJ!wGJg 4VW Neǘ::Aj213bx[+?(Z[(~Mf|vMq-/Y DCۀ1oxpSPaRN_-*]M:=*m1({w &:mm/+{cJwz&q_6I |"FRU%%rԊg޸@r+0iFB>뫉˞QS(5̩~ikzFr^TIUb(\ ut̺2+Nk`$yfL&D]lfW)%|6.LTgg\yJ;~C~vfl1õTܽl5jg(omn:gMYQ9 @^@wI@5i?rӀT|ŠH}xIaj _R2a;+_+Lvl & dw' 4x kՔG< aIKmSWo&Dɮ. d03T .SFzē>BAW dY( y3 nTޙ\[htMi搑 66yW$@~ھ+~`΂/] s9Ҵj]́޾ *\gⴼqCSVTXu"գ] E{HsmN{^^h+݇ o$d.GBӺ>}WQ&}Fe( S݊, D^>(BP>,HYf6Kzp8wpxv8݇gAj4SMCEOy[^ j.Daq F&a` }DrXH,Gխk9m՚ݤ{`uƣQY#Ít'xZOT3h':!`m8&UO,x]%IVǭ 6VF ySA<ҟ5=s~ dfoG_';>û4|<%Qaq\H<\PК: A+c*NCxo";) tAÚ}dQ*XTEUMh040CXAeN?v_4ƿrxQw(9+@/XByQ\zOIYK J%@h$D6jnN%A7,B[AG;Q# A5IE^0xZ!-PԇZLvՠ2udXgj^Yyø))0bJRxPqia9׭z/6)W6mXa^%b.dh ɀd8YL@ip`"VѨ~# 55~x|n% CNt+P) uܬ|=W"̹r`b`O kHor w2F8F`d>7Kcev;r/(${0fk4osOZ Z>128ݖBRTcK CðG|Oq-)8W?ӡDVߣŌ/?|nuK]D s#fU(V.r_v̈́vWeI&K5wr+ $ImC͢aHɗ|q/ZwR *'fy]9y" 7/YA_AˤPsxI#ؐT4SXOԠ6h4p?ηzPt`'o;(Dt:7/zgM߻ ieFO%e%Fvklu"Od^<ܩ|.%k%aSj&Pj#Du!AD~~kJ5RO!S-G ؒZd'KAzUxq!R gi|Gq +MS2v"Sf 7eQtJ*5qIw["Jo ;Q0TVܞc <*)Y` -(;bNgդqŞ6lax 8mudG:uň8@O_PE bkQZbm6ҲVHy©rʥ0Ǘ$K/cj/MQ qռ[$ǟ*`7024x$e~^tp UaNv% o߄PJ]K48 `7@Mah)<[Dϵh㥅SӑvT4ܭLcV4m"͋6E2PPYe0)b 40!ϙR M`$6:Vup!݇!ޟH slٔ mmBkUbu g5oߣ<+'.r2 AU+m۳Mx6W.F7,s¶a eeWp&~SVI۴.X9~t;M5ݰ}4UK$YlW3S@3@Z]V#m'?B۸l7v}ơN`BMȾ[ۺe_\0q,fa3IrB翂ZM1PO.qBM&X[4e9r.b4yݧ/q<5s;i'[ʌ ّ*e1J/3~?ɥw;/vNxɌ>T `18 ՖVr,Shr׫ùs 3|jә> yM!m 2EyK?V1їb>{'RR7&*b~k}읓,b*w㫔=Fb,?-Q-uw1/Myb`9ԺQi+&79~|=_(U6_"L&uv15PT*zazKO3_8\AvntŘ!2ٌ5K%O4g(H˗~0[y+;"0E9Ϲ4n})jQ\.zN~!)QUiS]kʄ"գԿ}Ir14} gNҲ!\Xb&ctk*7ؙXee†rSxHOr$>(ϲ*^i(Z&@eD N&T` D˒ ݩMf0FWJ"4v4"j &/˸nAȺ;Zݓ1zVW[Z;TA Jigs]gYߑLĸLR!4nb &ReA+ *=l][JMOj=b}V| +3rWu>ԅ$tV\Q+a3y/fM[INÞ{ZLck{T!!PrV8)[>d,Kޜc?o Ca2 K7c qc{̐ Ԛ-gh833zC~P ,B[Livf)=Nbn]8^p!)#Β/pM= 5R.oVU:mup Euԩ&OKELsE֧ oj:?KXR9>ܛ2N2r ,M RC-,Om里s`zDto@7č4"p=L.Zeem\#~W@`ΠF#k?wB/+7b Z~7 1\zBDž`.}`07zy?(t?c 48TɿwPb-?5[ڴo͵Ј ~Z۩䲍A7Q1EIX|:"1AKo#74V{Iy9B #*@chrXP[kM*gUDB*UQ .ƴ~CgaadNfGUYYddɾ:RxZYNDu;''f Eec ht^!☬tth;?;M'(d}Ӗ4{P ib&%&3cVRk F{1Yi]>gR%! >=-XL[H|‚i'IVocY9>;!3g拟ktfnW5YJf)BTbM-`%NkdgRgJ +{ Ռ0+^b>bj̊I tDWhfår9𣩲&HzI(Gi6~M fkؓS7Աό(7huw2}<//Tnr0@5% ;4kSs>7A #8RZD{bd7}n]TAnýi(6HkJ) G_@7=`l 2-\ˌ4Xs\Z?A_6L i2sz1]!V]k{*\w>J1}?PȺ<|(3soٟ2}gB;oc`跪^#C8uSf pxwHz,֗.~<6vLƆPP}JtX&'VZ<==QEŽ2f"wxrx:,2~mv#bBU#; 0':qIjLa`F7:XN}{T̉A@Y1weXT&be9u!17kG{Hr.'k(·xfCIGZm2/kicp2dNɮj7俢qR/SB+TXNti cv3Hd%3Ec;S?nkP]֞vk*1ȂNN 4D1PRwNH֠`>oxm&Ď4ՊP[3Rݰ#:f'TAmʍaH9mԁ@ V^l5. zlG,jVPD *M<ТqjߍꮰDVސkYJ(G^<{EHv=gF~F m'#TBq6r(w= m )X8bz-f@[/FLkp^a~5vӳ໢ES_7 XDsu ~P˲Pw%Ot[j FLՊ[@^BP+N?T2NNEԇm- {KfO8ZGC_ @/ϹJaBpc!{"Tx_Sɒcx۾g8Y 7NP8rzŀ2'9cSh2'@}FPv`g 7O&&x؃Na]+yLpATCHx&ۉ)"IX͠#gG@y<8%3%O%3@07"nױE;ݞl(GtSpm!BT?ߐaexgcbsT HMB֊Y))Ś(gط-2 2-nwh7{?MҨB7)G[T@-K`\R R)KāihT‚0+!޻sKӄC:ëqY5%?FR ΘqKϔyvc'e~ 楟TZnjt]à~Wh :F b!=*vt$y|ᓟY;s;{b 7j건M5]拸eƼf7'!PyHMv Fh>ⶃ~8X`jPpn#anp҃ԡ7ڽtLs/Պ|œU,p`/1~ALa"1AAQN|'!Y[|DOMҫo'"}*tpU9Up.>Bx ڳ2Eg͢4En>ޞ ɠU1)2werU|.,"Иy": iH?UdWB$?0sImJb!!c56(rZ$ aʬi;oSq(:ĥ6Iz"D-Do>>Jv6-~^i9YbfF (NjIi8:purƘtMD k{Z|i"gٝf‡{{Ŕ?"q]T91pܓQ,d:/tKNoBr$+hj/8r%$ߕ =ڪ1>0;?JYB7iK{nʩ23.^LH17u~.Sg-i䅁sQdi;Fvt{LX:ǶY`ƚqڏ꺪* x).٭lMJՀѐ8:>CltÌJrb*'#-[ƦidDh G) (n }]}L6vgz0wUOpc* nM@W%W}rX h~/:+jvEwoi!%_hI<^}gQ݀rLœ /=@,Z.mOLR'Yt-kV6AH12eA,F瘁#ʢ dJso%βaHPNT)t`ض s>}̇!)ϖQ{S8%"WrUq\~p ojza?i7 ]j神M 8v "y?E(T @u!n BJa}4#MHaY.;U#.}tH9E-`zH@ ,X,t -I'.WY& qxV{I57.✦U?t:Ik%bB">Q63(<ꢘ`wEglwImvd;kG#RY]-k]KWQ`@P7EdT}s P-cͪSwПLz%H zU{7z%_5>(P}0:|jl,vIDNg,bEʏMCDz<4lZhLj;<FÉOhյ _LV`r5&ݳĄ~’n%\vyqނ{!S%3<)~&>Z*"2#cNM J7NNX?p7$h[yGyg-_ /B;wggFFq92 L%C;fgpZCJ#(1݄k%ǭp%f~ 9u˄x}%D{~F4|^Z&}{(mFw**S`u/;58M 8?dH$*T/225}G[g8#Fx iybFcҠ38,* IA:ǫBB FqviDbȬB\nž;q&Rf)WT$aa{xu 2Պs&Mt^u["K4%531τrGز.x !f.,QŮ&9Vg4u7$rD©j~ipmZ %5>X:03%kL0Rvbo^jf&g;3$St6训&HG$' p~¸Zʓ>7S7UĎq4Jonc17SAYRiMmMiu@kh^B+W3-4B&R:._mO@`{L]Q߇ E`eV]$򲋆{}`GcR,o䦻Hc(o /lXBr0j*ޝ#Vo dJf|,Zqم+I#fqggiMoZs @VSϚ﵍5J|Hp2b#V΀/GZP%MWJG# $d1 i臭ova[-?)`w1ǿ?>~C9QpXB_.S[Kq$JV6QZF߫wLy&Ϋ 뀳r40RH%gjSo cx)X9~7m])mld@.OJ5/IAK*U7"W$썂s^ءLhp`m#ۧSa;S qY\}Bd X/'Tz-lDtoUW3Q} w\8(2qB,9)"a{<ݼt>]~Bh1#5 SmمI) A|Ogyqm'.VGO ªPR]\մ詠F?~Vz8"GKyM}LYO0(WYí^wpbl^Nι)$ w*%s-;;GH? &<1^v'{tyКHGq~C|%|Zbo~lp<牭 l}AA^rwVx{еyEYp۸,ISi2/M @$/8|lSՎSܗcʬLʍ@W$iT1R$ro +q׋p$Q,sfZqIMR,(}@Ƽ6Z)$uYUr -95R3 h?~Y>G+{z$xM\V'jn&X Pkyc@%l|Fj-hp&-5 !깤5 yYq!?YOp[qvyR &KF)hp%㩁?[Vg~˱#GBV\|m"A7UԳ%m[/@Na6>̈́m)a͞#C#n?DDw]8}*ZӚD,rz1U,L)]%,՛4^Ni^ V81%M>I{K~hRrZBNV=Uu$;Ih 2NܑD!SyX֝, [QXTչ)HfO̷V&?K) "+~Fn/T FSSz4~`3?f9"™/Үs?qpC/n39 0j$qK^1懾cQ\1ET@z}@ ߬9Ft#~'Ĉ_WG{ѣ3HRMpˬ;2E󠽉՜d kkQMpgvToZgRNkJCb C۠z`rn{1t#s̿B^?O4ޜ-ʪ9URmN-)͛ep]+_ee6nb5;MHV[mwqAcd8~f 6e@+>#Wa^SJ5=kaXrR伹.@Ꮩ\}>ӈ YK$ZK]=nBQpSl frgs514w2ݳȟUyd,ƓY:ǝDh DmDH]5x\25Z1 ]G3Y GF<(,yQrleP*1\ mPE>9D( LDj(r.n 24‹ƌߍ&_ևKHPl&gF4).>lLOІDo*L.w ʲ|/V\O;m0N^:^3n*úx)FiqD?P$حn |$Iy /ۿ{kJmgU2?֚~, YV;{S(5 FA6(zZkxL5F$:EA z[nԆ#26 &0L蟫/-cX6Xuk7[ xBDYr&_Yx=ρ.2S'J5zvP7Νm/iH?'ȫʣH!qıgi-L}?W𜢊[>* ٌDf[1Tzd;M@DAr/$Ko=SCiJLRTxcEp##X} u)h>x%( "HVRSVʃϻ.2Y9+fǴ')6HUWNb<[9<ִܙObH`NGA cE\+ˣGP 3S+&A@djaj7_ž3ǢZ,N:A\DRw؂ > Kkd@""j[|XB|`;@c~ ;ԛ=>Jr- *IXrpyy?w;x?Kdn' yuDu0cF0au͌y*aO\pOͰT T+ ]~Y3:F4}WuA߃j?+e'M`Dғp_ǹAx[`q+x2Hn~*Fo7Ĺh0јbNq+ZH|x1r(Ym{/a2xN+Wp pn\b`"_eOe#:V!$2l`V 1(8Ej͔,pJ?[?Yz@A~qU0}\=4z)Q3}:x)Ǣ׋7dίҭ5Qx*fyj.x-D%؈󾮢EI%[0ԦI2VeU<|MIX9ݸjG,")0P L(J SĚ_-ïJkbTj7,W[`?pB0=)p]SκaHIWI|22'"6 {3zI">ڪMd )\^'ҔFԯ)IH]=zQzx6"ߵaKN)~%qRژ`y6 I[{tWX1#]4%>ЬjjQ>;04"[ )eŹm 1;=l&^ҭS_c/vnwv&l-5x{B !Smtu< -JЩVDN#zu'"Idm֋"l}y똏47DF-\UAnU$8@yVlxz2;=pغ2⟏|h< .;Po"PE|1êT>cs6{3y xvԝ(u@;3[<%4JLs:X[ۄybuh&߆:B{並x; AUl {`h^bvʨJKz5*4)%cg[; yRIڹPo%F "^zN&hE(c5o#ƨIU'kq{W]iߞSSYu Mq ,R 7s.;]/cȺB6(4K#ѱsJ \GTM%/ZZ ljKt/'Z@HD*FE֍eA IHfoDMXV;:?HX,cK&te5];S, m{?ܔ(4+8-݆i9`l #sX¢$k+sPуo/${ s V O{8ŵ ]rFe "4P36 =10Wώ者E*UxO퇻`!s~P, `֮ +ӪnMpdՁ. M'԰}c }{L[𝳿|7DkmK&*TY0ꬶ_i/Y/e6LVQaOڕc|)6TUM/!VXOs3vi>hSo,!r=@уmqEsGX؜j.`g`9՝p i\i)bNީm*1)+j=O`q Lhv`\i)[nr t0 s,ҏwVeT|n ^_ȧ^Pc7++X^cFC*揈c0UL#ȑܨGJ{6#Fv4$Ɓ:" {}+{!ُ8sl 7r: &3v~đs~48bO"օmz(T,EZoSh:.)_.&OvmdvX}e^j;S(Y_q5?K,]Bׁjײ%UrϑAkS`EUg_Ꝁ鸘 qW̏,7b$Uzv#@f&ڐHU51lMH krfXIu;6:H~Λ *H+:T.ݠz]aI<$U\baH $cSTCH KoTm`67O D^9OJ\ svIy lT _Exi|aU'ls~Q3(_Ӓ0z} =S|QLx-y?̊%}*Y%^ iQ0Nkiߌ>w$/7zAWHU0>.P/Yq>OL(InS{c&}˺2" p^h&#Gq}d"tne8^}5l KWNy, G x30Dq,ҕ|S}r;*a`xY (uK)fr{J =07'ZvxYuO׭ww DqfvRˬ(q'Pr0}2NH+khzbMi}ZOjtV1{XL-lVm)J ĦkF >{7ũQ1o2|/{I;z+ ۮ "zY(A֦IJfĵ ciߠP 5ih6?8YB9 |3Gw/:GNh & Q\׋_!Z)}Bi-{U½ vLjHGT-\qj7\u'>b<K_|̖)[4'l`2ta!j6֖b1RdOOa?Fn?yZGCrxp[Pu{-s`cWKw$WY߶Y]6pr19UXy\-孃FR k{%<mNg(fKzLJ9IWVLhׄ5 D-Jk;\BQW5B\= K)68Me3ԁ[fG5n@Me? 8902^6sy[PAHbPU6-m'W&nsߺD D?3e (:ÔiU̇zƸKz̆, o`ܨIF/0q$M&S`to{TPQiT 78WPeђ20Af}s` ]SôޗĢ҄ؠO|nM@s!=j\]GC^#o4ߖB#$?l?=g>+g3 PPA Cc*IřԺg Ӳ"Ƈ5s\/;MES[10#5Zi6ypvںUJSU@k~L+,Yf4D|Б%=e)/9=#0[1::Ly \CDIQ\ܞ;-PחK2! _Wpp\BU2CD2~wߚnL?8\?(B48+/\Ƿk#ev8p / <ɕ,ih.Åܒ&(X)T r*|K}6~Ȋvg2.$Oh=Wէ0|?n%-V2ɉB6 K"JqHC?$A|Z{Tž&m"TM1[0lEzou7O"nx=@`4|7*qLQ~Ici$rm|uM:wD<sNQ| ?"A4#=͠yk5o aOҽ݉Ž Dt+n>|2C|Nc!f;nf@:bMQ^^+E);\Ru*^ Ꟗeغpʠb/+QvV\QƩ4{R a~bz6#.3I,A Yxch>Rq΃,LE+oզG,yJ7発bCS[EtC64R&FtSbH|o3Nj ѫ||-4crMFZx?1pLdϛAmoH"d|XݫcHMz2@b7x_%N#?&};ƣŤ1/0'Y0f5n w-q?}LA^OFCܵ淋 hM՟O>* ;ś׸{4m(JRt}VYN ,3!6o~а*'zh!Ztx:Ϧ bɸ qA@w1ލWO;ۖI S5t 9q? $9•^ql m Q5Ac ߣ *L ZόV_] ?tԩbVj!`5d/%Gl|`yzkExg?4:&l+V3/08ɖ-X2a[; dF,1d"-jzpzD6'0PKBON7P:Sx KM!N%Ό@GPt& Cu6dv?{a BHV?+K ,9W)ǫIX~bbl`~ZJz[bLv!?g CD"DHv$^:uqҶW"[OpqI;r@ <%BLoZ oqUS 5n~_A 5w$~;f$,rƁ/|f]_\As>:t'5݄5 e QkϕR^OTO'_s8p<̅Vdz$4qƉ[kZBHx8myT"CÍfj6ǿx΍sg~vyee_4,g?7>+uzٜ=.#..7Q|NGfT*cD$c\Ϲ}ٛ&+舗۪.CY0-F]$g=a>vadjSvS#CcC +[zh򿯃؆P± nDѕ㍐Wb 'Y2Φ!t7FGs$ շ<^B6L%*[NKwn E 9A&[jE@}*erm?^_Rn߰>~]C+@g D@NAᯕQ$~ "&x5_[ ->@n>ETܻ}&k;v pVGKHAGq)#j.3A2HE7W-r;:Ѱ% V9FYqg7Dxw=Dz" ݙSۙQhOnJASe,t#>%#wBPpnƿ6@7<>,뀂}/PV.A[Jvdx`XC(er1/oAJ^eS>~k!+bb IjX= RȏI`d7x uxz_ iiEJ*zz%0Yv(/Ép97Z^WLp.fPE6x tڤm>:] pٌp gCް(Yv>h(&6kv[G2$hfǗuwHF蛺ZF dNӓ][U2EKVK{|ރx@Gtx^Z~w0#Qv3ԄC(f8?mU!r?aMGƎ!~R=!|gsI.Ǿ`9ƇdE hQ;X:Z@5K 3A9uZ6f5*Jێ9WuN:*"ǎd]#$.-='BU]%Zj}x0t8+URɠ|D{wN>&oii{!HB/HJj9 pF#1unqgՓ  "Dj YZ